Security Briefing | June 16, 2026 - Fortinet FortiSandbox Exploited, China Expands SprySOCKS to Windows, CISA Flags LiteSpeed Flaw
Threat actors are actively exploiting three Fortinet FortiSandbox vulnerabilities including a critical path traversal flaw (CVE-2026-39813, CVSS 9.1). China-linked espionage groups have expanded the SprySOCKS backdoor to Windows, targeting government organizations in at least four countries. CISA has added a LiteSpeed cPanel privilege escalation flaw to its KEV catalog with a patching deadline of June 18, 2026.
By EACA Summit Content Team

1. Fortinet FortiSandbox Flaws Exploited in Attacks
Threat actors are actively exploiting three vulnerabilities in Fortinet FortiSandbox, including a critical path traversal flaw (CVE-2026-39813, CVSS 9.1). The exploitation was observed by Defused Cyber and reported by multiple sources. Patches are available for some of the flaws.
Verified Facts
- CVE-2026-39813 is a path traversal vulnerability in FortiSandbox JRPC API with CVSS 9.1
- CVE-2026-39808 and CVE-2026-25089 are also being exploited
- Exploitation observed by Defused Cyber within the past 24 hours
Evidence
- CVE-2026-39813
- CVE-2026-39808
- CVE-2026-25089
Impact
Organizations using FortiSandbox should immediately apply available patches and monitor for signs of compromise. These flaws could allow remote code execution or unauthorized access.
Confidence Level: High
The Hacker News | BleepingComputer
2. China-Linked SprySOCKS Backdoor Expands to Windows

ESET has discovered two Windows variants of the previously Linux-only SprySOCKS backdoor, used in attacks against government organizations in at least four countries. The variants, WIN_DRV and WIN_PLUS, include driver-based stealth capabilities and hard-coded C2 configurations.
Verified Facts
- Two Windows variants of SprySOCKS discovered: WIN_DRV and WIN_PLUS
- Used in attacks targeting government organizations in at least four countries
- Variants support TCP, UDP, and include driver-based stealth
Evidence
- ESET report shared with The Hacker News
- BleepingComputer reporting
Impact
Defenders should monitor for SprySOCKS indicators on Windows systems, particularly in government and research networks. The driver-based stealth makes detection more challenging.
Confidence Level: High
The Hacker News | BleepingComputer
3. CISA Flags LiteSpeed cPanel Plugin Flaw Exploited in Attacks
CISA has added CVE-2026-54420, a privilege escalation vulnerability in the LiteSpeed cPanel plugin, to its Known Exploited Vulnerabilities catalog. Federal agencies are required to patch by June 18, 2026. The flaw allows root privilege escalation.
Verified Facts
- CVE-2026-54420 is a privilege escalation vulnerability in LiteSpeed cPanel plugin with CVSS 8.5
- Added to CISA KEV catalog on June 16, 2026
- FCEB agencies must patch by June 18, 2026
Evidence
- CVE-2026-54420
- CISA KEV catalog entry
Impact
Organizations using LiteSpeed cPanel plugin should prioritize patching. This vulnerability is actively exploited and could lead to full server compromise.
Confidence Level: High
The Hacker News | BleepingComputer
Also Noted
China-linked espionage groups have also been observed abusing Google Workspace rules for data exfiltration. Organizations using Google Workspace should review mail filter rules and forwarding configurations for unauthorized changes.
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



