CISA Orders Federal Agencies to Patch Exploited Fortinet FortiSandbox Flaws by Sunday
CISA has ordered federal agencies to patch two critical vulnerabilities in Fortinet's FortiSandbox threat detection platform by Sunday, July 19. The flaws, tracked as CVE-2026-39808 and CVE-2026-25089, allow unauthenticated attackers to execute remote code through command injection attacks that require no user interaction. Both vulnerabilities have been added to CISA's catalog of known exploited vulnerabilities, confirming active abuse in the wild.
Threat intelligence firm Defused first reported in-the-wild exploitation of these vulnerabilities on June 16, noting that attackers had begun actively targeting FortiSandbox deployments. Fortinet addressed the issues in patches released on April 14 and June 9, respectively, but had not publicly flagged them as exploited. The Defused report also mentioned a third vulnerability, CVE-2026-39813, which had no previously recorded exploitation before being observed in attacks.
Fortinet products remain a frequent target in cyber espionage and ransomware campaigns, with CISA tracking 28 Fortinet vulnerabilities exploited over recent years, 13 of which have been used in ransomware attacks. Under Binding Operational Directive 26-04, federal agencies are required to remediate known exploited vulnerabilities within strict deadlines. This latest directive underscores the ongoing risk Fortinet flaws pose and the importance of rapid patching across all affected deployments.