CISA Orders Emergency Patching of Exploited FortiSandbox Flaws

CISA has added two critical FortiSandbox command-injection vulnerabilities, CVE-2026-39808 and CVE-2026-25089, to its Known Exploited Vulnerabilities catalog following confirmed exploitation. The flaws carry CVSS scores of 9.1 and can allow attackers to execute unauthorized commands, with CVE-2026-25089 requiring no authentication. Fortinet addressed the affected deployments in FortiSandbox 4.4.9 and 5.0.6, while US federal agencies were instructed to patch or mitigate the vulnerabilities. CISA has not linked the exploitation to ransomware activity.

Reference: infosecurity-magazine.com