mimile
mimile.ai
Back to feed

CISA adds two Fortinet flaws to exploited vulnerabilities catalog

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

The US Cybersecurity and Infrastructure Security Agency (CISA) added two critical FortiSandbox vulnerabilities, CVE-2026-39808 and CVE-2026-25089, to its Known Exploited Vulnerabilities catalog on July 16, citing evidence of active exploitation. Both flaws carry a CVSS severity rating of 9.1 and allow attackers to execute unauthorized commands. CISA ordered federal agencies to apply patches by July 19.

The Vulnerabilities

CVE-2026-39808, an OS command injection flaw affecting FortiSandbox versions 4.4.0 to 4.4.8, was discovered by KPMG Spain researcher Samuel de Lucas Maroto and disclosed by Fortinet on April 14. CVE-2026-25089, affecting multiple versions including 5.0.0-5.0.5 and 4.4.0-4.4.8, was identified by Fortinet's own Adham El Karn and disclosed on June 9. Both allow unauthenticated attackers to execute arbitrary commands via crafted HTTP requests.

Patches and Response

Fortinet released patches in FortiSandbox versions 4.4.9 and 5.0.6. CISA required all US federal agencies to apply these mitigations by July 19, and for cloud-based services to discontinue use if patches are unavailable. The agency has not confirmed whether the flaws have been used in ransomware campaigns.

What's Next

Federal agencies must meet the July 19 deadline to patch the vulnerabilities. It remains unclear if the exploits will be linked to broader ransomware operations.

1 source

CISA adds two Fortinet flaws to exploited vulnerabilities catalog