CVE Tools

CISA urges immediate action on actively exploited Fortinet flaws

BleepingComputerBy Sergiu Gatlan

Reported exploitedFortiSandbox

Our summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning for government agencies to address two actively exploited vulnerabilities in Fortinet’s FortiSandbox threat detection platform. These flaws, CVE-2026-39808 and CVE-2026-25089, enable unauthenticated attackers to execute arbitrary code remotely without user interaction. CISA added both to its catalog of known exploited vulnerabilities and requires federal agencies to apply patches by July 19. Threat intelligence firm Defused confirmed ongoing exploitation attempts, prompting immediate action from administrators.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store