INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Fortinet FortiSandbox Vulnerability Exploit Found

| 2026-07-18 11:49 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The Fortinet FortiSandbox and Microsoft SharePoint vulnerabilities have been added to the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog. These flaws, tracked as CVE-2026-25089 and CVE-2026-39808 respectively, allow unauthorized access to remote code execution on affected systems. The vulnerabilities were identified in July 2026 and are expected to be patched by the due date of July 19, 2026. CISA has ordered federal agencies to urgently fix these flaws to protect their networks against attacks exploiting the vulnerabilities.
Technical Mitigations AI-generated
* Implement a secure coding practice to prevent OS command injection vulnerabilities, such as validating user input and sanitizing data before using it. * Regularly update and patch Fortinet products with the latest security patches to ensure that known exploits are addressed. * Configure network firewalls and intrusion detection systems (IDS) to block HTTP requests from untrusted sources, preventing attackers from executing arbitrary commands on affected devices. * Use a web application firewall (WAF) or content security policy (CSP) to restrict access to sensitive data and prevent deserialization attacks in Microsoft SharePoint applications.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-39813CVE-2026-39813 CVE-2026-58644CVE-2026-58644 CVE-2025-61624CVE-2025-61624 CVE-2026-25089CVE-2026-25089 CVE-2026-21643CVE-2026-21643 CVE-2026-39808CVE-2026-39808
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment
Incident Timeline
‎April 14
Threat actors used a known exploited vulnerability in Fortinet's FortiSandbox to target an unknown entity.
vulnerability CVE-2026-39808
target_region Spain
tactic T1588.005 - Exploits
organisation KPMG Spain
organisation Fortinet
general_metric 39808 CVE-2026
‎June 9
The U.S. CISA added the CVE-2026-25089 vulnerability to its Known Exploited Vulnerabilities catalog on June 9.
vulnerability CVE-2026-25089
‎June 16
Threat actors started abusing the Fortinet FortiSandbox and Microsoft SharePoint vulnerabilities in the wild.
attribution BleepingComputer
‎July 16
CISA added Fortinet's FortiSandbox and Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog on July 16.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
‎April 14 and June 9
Threat actors exploited CVE-2026-25089 and CVE-2026-39808 vulnerabilities in Microsoft SharePoint.
vulnerability CVE-2026-25089
vulnerability CVE-2026-39808
‎2026/07/18
U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to prioritize patching two actively exploited vulnerabilities in Fortinet's FortiSandbox threat detection platform.
organisation CVSS
organisation CVE-2026
organisation Fortinet FortiSandbox
organisation FortiSandbox
infrastructure 4.4.9
organisation Fortinet
organisation SQL
organisation the FortiClient Enterprise Management
organisation EMS
organisation Defused
infrastructure 4.4.0
infrastructure 4.4.8
organisation Fortinet’s FortiSandbox
infrastructure 5.0.0
infrastructure 5.0.5
infrastructure 4.2
infrastructure 5.0.4
infrastructure 5.0.6
organisation Shutterstock.com
organisation EDR
‎July 19, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to fix known exploited vulnerabilities in Fortinet's FortiSandbox software by July 19, 2026.
‎July 2026
Microsoft's July 2026 Patch Tuesday addressed the SharePoint remote code execution bug CVE-2026-58644.
vulnerability CVE-2026-25089
vulnerability CVE-2026-39808
vulnerability CVE-2026-58644
vulnerability CVSS score of 9.8
tactic Remote Code Execution
organisation CVSS
organisation Microsoft
organisation SharePoint
organisation CVE-2026
general_metric 58644 CVE-2026
organisation KeV
organisation FortiSandbox
infrastructure Microsoft Office
organisation Microsoft Office SharePoint
‎July 19
The U.S. CISA added Fortinet FortiSandbox and Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog, prompting a July 19 deadline for federal government agencies to roll out patches.
industry Government
‎Sunday, July 19
Threat actors exploited vulnerabilities in Fortinet's FortiSandbox and Microsoft SharePoint to target U.S. federal agencies, with patches required by July 19.
attribution FortiSandbox
general_metric 26 Binding Operational Directive
Tactical Metrics
Metrics
infrastructure
‎Microsoft Office
Affected Product
Metrics
infrastructure
‎4.4.0
Software Version
Metrics
infrastructure
‎4.4.8
Software Version
Metrics
infrastructure
‎4.4.9
Software Version
Metrics
infrastructure
‎5.0.0
Software Version
Metrics
infrastructure
‎5.0.5
Software Version
Metrics
infrastructure
‎4.2
Software Version
Metrics
infrastructure
‎5.0.4
Software Version
Metrics
infrastructure
‎5.0.6
Software Version