CISA Confirms Active Exploitation of Critical FortiSandbox Bugs — Patch Now or Pull the Plug
Fortinet admins are having another rough week. CISA has added two critical FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming what security researchers had already started flagging: someone is actively poking at these things.
The two flaws in question, CVE-2026-39808 and CVE-2026-25089, both score 9.1 on the CVSS scale and affect FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. They are OS command injection vulnerabilities, meaning an unauthenticated attacker can fire off specially crafted HTTP requests and execute arbitrary commands. No credentials needed. No user interaction required. Not great.
Fortinet shipped patches for CVE-2026-39808 in April and CVE-2026-25089 in June, with advisories noting that both could lead to remote code execution via low-complexity attacks. The company has not publicly acknowledged exploitation in the wild and apparently did not respond to questions from The Register. Its advisories remain unmarked.
CISA's KEV catalog does not come with detailed threat intelligence attached. The agency confirmed exploitation is occurring but, as usual, offered no attribution and no sense of scale. What it did do is trigger obligations for federal civilian agencies under Binding Operational Directive 26-04: patch within the specified deadlines or, if that is not feasible, pull vulnerable systems offline.
Outside government circles, security firm Defused reported observing active exploitation attempts against both CVEs this week, along with a third FortiSandbox flaw, CVE-2026-39813. One caveat worth noting: Defused described the exploit targeting CVE-2026-25089 as appearing to be "vibecoded" and probably broken, with no working public exploit spotted yet. So some of the activity may be noisier than it is effective, at least for now.
CISA also used the same KEV update to flag a freshly patched Microsoft SharePoint Server vulnerability, CVE-2026-58644. This one is a deserialization flaw rated 9.8 and requires an authenticated attacker with Site Owner privileges to trigger remote code execution. Microsoft noted it is exploitable over the internet without significant technical barriers, which puts it firmly in the "do not sit on this" category.
Three critical vulnerabilities across Fortinet and Microsoft infrastructure, all confirmed or flagged for active exploitation in the same week. Business as usual, apparently.