Fortinet, Ivanti and SAP released security updates this week for multiple critical vulnerabilities that could allow arbitrary code execution and information disclosure, and the clustering is the story. The Fortinet fix addresses a command injection flaw in FortiSandbox, FortiSandbox Cloud and the FortiSandbox PaaS web interface, tracked as CVE-2026-25089 with a CVSS score of 9.1. Ivanti and SAP shipped their own critical patches in the same window.

The shift worth flagging is not that three vendors patched on the same week. It is that the most dangerous flaws keep landing in the security and edge infrastructure that sits at the perimeter, the very devices bought to keep attackers out. For CISOs, that inverts a comfortable assumption. A sandbox appliance, a VPN gateway or an ERP front end is not a defensive asset when it carries a 9.1 command injection bug. It is an externally reachable code execution surface with privileged network position.

The original insight is about timing, not just inventory. As time to exploit compresses toward a single day, the gap between a vendor advisory and live exploitation is collapsing, and edge appliances are where that gap is most punishing because they are internet facing by design. We have already covered a security gateway under active exploitation, and the pattern repeats: attackers pre map a vendor’s exposed asset landscape and move within hours of public disclosure. The practical implication for security operations is to treat advisories for perimeter and security appliances as a distinct, expedited patch class with its own service level, separate from general server patching, and to assume that anything internet facing with a critical rating is being targeted before the maintenance window opens.

Source: The Hacker News.