CrowdSec logged in-the-wild exploitation of Fortinet's FortiSandbox appliance on 17 June, the same day it shipped a detection rule for CVE-2026-39808, an operating-system command-injection flaw. CISA did not add the bug to its Known Exploited Vulnerabilities (KEV) catalogue until 16 July, a one-month gap 1.
That KEV entry starts the Binding Operational Directive (BOD) 26-04 patching clock for federal agencies . Private detection therefore ran a month ahead of the federal catalogue meant to trigger the mandatory deadline, while CISA works through the FY27 staffing cuts already on this topic's record. CrowdSec is a French crowdsourced threat-intelligence firm, one of several private feeds that now lead the federal list for the defenders who subscribe.
FortiSandbox extends the Fortinet exposure the beat has followed since the FortiBleed credential haul , which SOCRadar tied to Lynx and INC Ransom and later to twelve ransomware deployments . The KEV record still lists the flaw's ransomware association as Unknown, so the crew adopting it has not yet been named.
