logo

CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities

ID: 79101a8d-8c37-5811-9005-1c4efdf523f5

STIX ID: report--79101a8d-8c37-5811-9005-1c4efdf523f5

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

...
...

CISA warns that two critical FortiSandbox OS command-injection vulnerabilities (CVE-2026-39808 and CVE-2026-25089, CVSS 9.1) have been observed exploited in the wild; both were added to CISA's KEV catalog and Fortinet has released patches (e.g., FortiSandbox 4.4.9 and 5.0.6) with agencies urged to apply mitigations or discontinue cloud services if unable to mitigate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.