CISA has added two critical FortiSandbox vulnerabilities (CVE-2026-39808 and CVE-2026-25089), both scoring 9.1, to its Known Exploited Vulnerabilities catalog, confirming active exploitation. The OS command injection flaws allow unauthenticated attackers to execute arbitrary commands via crafted HTTP requests, with fixes already released by Fortinet in April and June. CISA also flagged a critical Microsoft SharePoint Server deserialization flaw (CVE-2026-58644, CVSS 9.8), which enables authenticated attackers with Site Owner privileges to remotely execute arbitrary code.