Attackers target critical FortiSandbox flaws as CISA issues patch order
What happened
CISA added two FortiSandbox vulnerabilities (CVE-2026-39808 and CVE-2026-25089) to its Known Exploited Vulnerabilities list after researchers observed exploitation attempts. Both are OS command-injection flaws affecting FortiSandbox appliances and cloud offerings and can allow unauthenticated remote command execution; verify patch application, apply mitigations on inspection nodes, and watch for any federal remediation directives
Why the category manager should care
Treat this as a real demand for remediation because CISA KEV listing indicates active exploitation and heightened regulatory attention
Key facts
- Two FortiSandbox CVEs added to CISA's KEV
- Vulnerabilities enable unauthenticated OS command execution
- Vendor fixes previously published; evidence of in-the-wild exploitation observed by researchers