What happened
Fortinet, Ivanti, and SAP each released security patches this week addressing multiple critical vulnerabilities, including a command injection flaw in Fortinet's FortiSandbox product line — tracked as CVE-2026-25089 with a CVSS score of 9.1 — that could allow attackers to execute arbitrary code remotely. The flaws span cloud, on-premises, and SaaS environments, broadening the potential attack surface considerably. Separately, security journalist Brian Krebs published an investigation into the ransomware collective known as The Gentlemen, currently ranked as the second most prolific ransomware group by confirmed victim count. The group has grown rapidly by offering affiliates an unusually generous 90 percent cut of ransom proceeds, drawing skilled operators into its network at speed.
Why it matters for your business
Unpatched vulnerabilities in widely deployed enterprise platforms like FortiSandbox, Ivanti, and SAP products represent high-priority targets for ransomware operators looking for initial access footholds. The emergence of The Gentlemen — with its aggressive affiliate revenue model — signals that the ransomware-as-a-service economy continues to industrialize, making attacks more frequent and better resourced. Organizations running any of the affected Fortinet, Ivanti, or SAP products should treat these patches as emergency-level updates and apply them ahead of scheduled maintenance windows. Security teams should also audit third-party and affiliate-managed access points, as high-commission affiliate models mean a wider pool of actors actively scanning for vulnerable systems.
What to watch next
Krebs's investigation suggests investigators are narrowing in on a real-world identity for The Gentlemen's administrator, which could trigger law enforcement action or cause the group to rebrand — a common ransomware survival tactic. On the vendor side, watch for proof-of-concept exploit code targeting the newly disclosed CVEs to surface in the coming days, which would sharply shorten the safe patching window for enterprise teams still in the remediation queue.
