# CISA adds Fortinet, SharePoint bugs to KEV

Published: 2026-07-16 · Severity: high · Sectors: government-national
Canonical: https://vorant.io/reports/48ede7bc-4086-53af-a6ef-75c80f2a5923/cisa-adds-fortinet-sharepoint-bugs-to-kev

> CISA added three actively exploited vulnerabilities in Fortinet FortiSandbox and Microsoft SharePoint to its Known Exploited Vulnerabilities catalog, mandating federal remediation.

CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation: two OS command injection flaws in Fortinet FortiSandbox (CVE-2026-25089 and CVE-2026-39808) and a deserialization of untrusted data vulnerability in Microsoft SharePoint (CVE-2026-58644). No details on the exploiting actors, malware, or specific attack chains were provided in this advisory.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of these vulnerabilities on publicly exposed assets, particularly those that could grant an attacker total control post-exploitation, and to check for prior compromise before patching. While the directive is binding only on federal agencies, CISA recommends all organizations running FortiSandbox or SharePoint apply available patches and mitigations promptly given confirmed in-the-wild exploitation.

This is a routine KEV catalog update rather than a novel campaign disclosure; the significance lies in the confirmed active exploitation status of these three CVEs, warranting expedited patching by any organization using the affected Fortinet and Microsoft products.

## Mentioned in this report

- Vulnerabilities: CVE-2026-25089 (KEV), CVE-2026-39808 (KEV), CVE-2026-58644 (KEV)

Source reporting: https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/48ede7bc-4086-53af-a6ef-75c80f2a5923/cisa-adds-fortinet-sharepoint-bugs-to-kev.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
