Attackers target critical FortiSandbox flaws as CISA issues patch order
What happened
CISA added two critical FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities catalog after evidence of exploitation. Fortinet released fixes earlier but the KEV listing elevates urgency for buyers to identify and patch or isolate affected appliances. Procurement should verify support entitlements and whether emergency supplier costs or contractual remedies apply
Why the category manager should care
Immediate asset identification and patch/mitigation are required because active exploitation evidence elevates operational risk and may trigger regulatory obligations
Key facts
- Two FortiSandbox vulnerabilities added to CISA's KEV list
- Advisories and fixes previously released by Fortinet; CISA inclusion signals active exploitation