logo

U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog

ID: 09e019fd-d3fa-57cb-ae0a-25d6cb3cbb6c

STIX ID: report--09e019fd-d3fa-57cb-ae0a-25d6cb3cbb6c

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

Author: Pierluigi Paganini

...
...

CISA added three critical vulnerabilities to its Known Exploited Vulnerabilities catalog: two Fortinet FortiSandbox OS command injection flaws (CVE-2026-25089, CVE-2026-39808) and a Microsoft SharePoint deserialization vulnerability leading to unauthenticated remote code execution (CVE-2026-58644), all scored at 9.8; Microsoft and third parties report active exploitation and CISA has directed federal agencies to remediate by July 19, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.