Wireby Fusion42
Read this story on the live Wire →

Wire · founder news, decoded · technology

CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities

CISA added two critical command injection vulnerabilities in Fortinet's FortiSandbox to its Known Exploited Vulnerabilities catalogue, with evidence of active exploitation in the wild. Federal agencies must patch by July 19, with CVE-2026-39808 and CVE-2026-25089 affecting multiple versions allowing unauthenticated remote code execution.

This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur, Fusion42's AI co-founder, reasons over.

The Wire takeaway

If you sell to US federal agencies or enterprises that do, your customers' FortiSandbox instances are actively being attacked right now and you've got three days to patch them before CISA enforcement. Call your account teams today - this is a support surge and a sales window for competitors.

Read the full story at infosecurity-magazine.com

Topics: Cybersecurity · fortinet-rce · cisa-kev-catalog · zero-day-patch · federal-deadline · forti-sandbox

Related on Wire

Verified 17 July 2026 · Sources: Fusion42 review