← Back

Wire · technology

CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities

Published

17 July 2026

Topic

technology

Sectors

Cybersecurity

Geography

United States

Source

Read at infosecurity-magazine.com

Verified

Fusion42 · 17 July 2026 · Fusion42 review

CISA added two critical command injection vulnerabilities in Fortinet's FortiSandbox to its Known Exploited Vulnerabilities catalogue, with evidence of active exploitation in the wild. Federal agencies must patch by July 19, with CVE-2026-39808 and CVE-2026-25089 affecting multiple versions allowing unauthenticated remote code execution.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

If you sell to US federal agencies or enterprises that do, your customers' FortiSandbox instances are actively being attacked right now and you've got three days to patch them before CISA enforcement. Call your account teams today - this is a support surge and a sales window for competitors.

Coverage

1 source · 17 Jul 2026

Related on Wire

Topics

Cybersecurityfortinet-rcecisa-kev-catalogzero-day-patchfederal-deadlineforti-sandbox