CISA added critical Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed in-the-wild exploitation. The US federal patching deadline is Sunday, but active exploitation means UK organisations should treat this as immediate priority. A newly published Windows local privilege escalation vulnerability called LegacyHive works on fully patched systems with no fix available, creating serious risk when combined with active ClickFix campaigns delivering initial access. ClickFix techniques now support at least five concurrent malware operations including ACR Stealer, Starland RAT, TELEPUZ, Potemkin Loader, and TTF campaign payloads. A Huntress case study documents how one ClickFix compromise spread to eleven hosts before detection. The episode provides specific, actionable guidance for SMBs: verify FortiSandbox patch status with IT providers today, brief staff on ClickFix lures immediately, review user permissions to execute scripts, and ensure endpoint detection monitors for HTA execution and PowerShell spawning from browser processes. The convergence of mature exploit infrastructure, public zero-day proof-of-concept, and active campaigns targeting European users represents a significant immediate threat to UK small business networks.