CISA urges immediate action on actively exploited Fortinet flaws
ID: 23697dfb-5f40-5c70-8c80-b70b9d03d3db
STIX ID: report--23697dfb-5f40-5c70-8c80-b70b9d03d3db
Feed Name: Bleeping Computer
CISA ordered U.S. federal agencies to urgently prioritize patching two critical Fortinet FortiSandbox vulnerabilities (CVE-2026-39808 and CVE-2026-25089) that allow unauthenticated remote command injection and have been observed exploited in the wild; Fortinet released patches on April 14 and June 9 and agencies must remediate by July 19 under BOD 26-04. Threat intelligence firm Defused reported active exploitation, and the advisory references other Fortinet flaws previously abused in espionage and ransomware campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
