VORANT. Threat Intelligence Sign in Get the full feed

CISA adds Fortinet, SharePoint bugs to KEV

high vulnerability government-national

CISA added three actively exploited vulnerabilities in Fortinet FortiSandbox and Microsoft SharePoint to its Known Exploited Vulnerabilities catalog, mandating federal remediation.

CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation: two OS command injection flaws in Fortinet FortiSandbox (CVE-2026-25089 and CVE-2026-39808) and a deserialization of untrusted data vulnerability in Microsoft SharePoint (CVE-2026-58644). No details on the exploiting actors, malware, or specific attack chains were provided in this advisory.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of these vulnerabilities on publicly exposed assets, particularly those that could grant an attacker total control post-exploitation, and to check for prior compromise before patching. While the directive is binding only on federal agencies, CISA recommends all organizations running FortiSandbox or SharePoint apply available patches and mitigations promptly given confirmed in-the-wild exploitation.

This is a routine KEV catalog update rather than a novel campaign disclosure; the significance lies in the confirmed active exploitation status of these three CVEs, warranting expedited patching by any organization using the affected Fortinet and Microsoft products.

Mentioned in this report

Vulnerabilities CVE-2026-25089KEVCVE-2026-39808KEVCVE-2026-58644KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free