Fresh Fortinet Vulnerabilities Require Urgent Attention
Fortinet administrators, mark your calendars because CISA has some significant news for you: two major FortiSandbox vulnerabilities are making waves. Identified as CVE-2026-39808 and CVE-2026-25089, both are rated with a CVSS score of 9.1, affecting FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. These vulnerabilities involve OS command injection, allowing any daring hacker to execute arbitrary commands via sophisticated HTTP requests. No need for legitimate credentials or even a chat with the user!
Fortinet’s Action and CISA’s Advisory
Fortinet released patches for CVE-2026-39808 in April and addressed CVE-2026-25089 in June. They cautioned that these vulnerabilities could enable remote code execution through low-complexity attacks. However, Fortinet has remained somewhat reticent regarding the flaws being exploited in the wild. CISA, conversely, has included both in its Known Exploited Vulnerabilities (KEV) catalog, indicating increased severity.
CISA’s Guidelines and Additional Findings
For personnel in federal civilian agencies, KEV vulnerabilities come with specific requirements. Operational Directive 26-04 mandates that they must apply patches immediately or remove the vulnerable products if they cannot secure them. Fortinet has not modified their advisories to indicate that the vulnerabilities are being exploited, nor have they responded to GadgetLad’s detailed inquiries. Meanwhile, security firm Defused has reported attempts at exploitation, describing one exploit as “vibecoded” and potentially ineffective.
New Issues Emerging: SharePoint Server Vulnerability
While FortiSandbox is in the limelight, CISA has also highlighted another vulnerability: Microsoft’s patched SharePoint Server issue, CVE-2026-58644. This one is a critical deserialization vulnerability with a rating of 9.8. Any attacker with Site Owner privileges could leverage this to execute arbitrary code remotely. Microsoft’s warning is unequivocal: this vulnerability is easily exploitable over the internet, so patch it quickly!
Conclusion: Oh No, More Vulnerabilities!
Well everyone, it seems it’s patching season once again! Fortinet’s FortiSandbox and Microsoft’s SharePoint Server are causing tech professionals to race against time. Whether due to CISA’s notifications or Defused’s reports of suspicious exploits, don’t say GadgetLad didn’t alert you. Get those patches applied and then you can head back to the pub!