INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Fortinet FortiSandbox Vulnerability Exploit Found
| 2026-07-18 11:49 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The Fortinet FortiSandbox and Microsoft SharePoint vulnerabilities have been added to the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog. These flaws, tracked as CVE-2026-25089 and CVE-2026-39808 respectively, allow unauthorized access to remote code execution on affected systems. The vulnerabilities were identified in July 2026 and are expected to be patched by the due date of July 19, 2026. CISA has ordered federal agencies to urgently fix these flaws to protect their networks against attacks exploiting the vulnerabilities.
Technical Mitigations AI-generated
* Implement a secure coding practice to prevent OS command injection vulnerabilities, such as validating user input and sanitizing data before using it.
* Regularly update and patch Fortinet products with the latest security patches to ensure that known exploits are addressed.
* Configure network firewalls and intrusion detection systems (IDS) to block HTTP requests from untrusted sources, preventing attackers from executing arbitrary commands on affected devices.
* Use a web application firewall (WAF) or content security policy (CSP) to restrict access to sensitive data and prevent deserialization attacks in Microsoft SharePoint applications.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-39813CVE-2026-39813
CVE-2026-58644CVE-2026-58644
CVE-2025-61624CVE-2025-61624
CVE-2026-25089CVE-2026-25089
CVE-2026-21643CVE-2026-21643
CVE-2026-39808CVE-2026-39808
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
Incident Timeline
April 14
Threat actors used a known exploited vulnerability in Fortinet's FortiSandbox to target an unknown entity.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-39808
ForitSandbox Exploits Can Lead to Execute Rogue Commands
CVE-2026-39808 was detected by Samuel de Lucas Maroto, a security researcher at KPMG Spain, and disclosed by Fortinet on April 14.
target_region
Spain
ForitSandbox Exploits Can Lead to Execute Rogue Commands
CVE-2026-39808 was detected by Samuel de Lucas Maroto, a security researcher at KPMG Spain, and disclosed by Fortinet on April 14.
tactic
T1588.005 - Exploits
ForitSandbox Exploits Can Lead to Execute Rogue Commands
CVE-2026-39808 was detected by Samuel de Lucas Maroto, a security researcher at KPMG Spain, and disclosed by Fortinet on April 14.
organisation
KPMG Spain
ForitSandbox Exploits Can Lead to Execute Rogue Commands
CVE-2026-39808 was detected by Samuel de Lucas Maroto, a security researcher at KPMG Spain, and disclosed by Fortinet on April 14.
organisation
Fortinet
ForitSandbox Exploits Can Lead to Execute Rogue Commands
CVE-2026-39808 was detected by Samuel de Lucas Maroto, a security researcher at KPMG Spain, and disclosed by Fortinet on April 14.
general_metric
39808 CVE-2026
ForitSandbox Exploits Can Lead to Execute Rogue Commands
CVE-2026-39808 was detected by Samuel de Lucas Maroto, a security researcher at KPMG Spain, and disclosed by Fortinet on April 14.
June 9
The U.S. CISA added the CVE-2026-25089 vulnerability to its Known Exploited Vulnerabilities catalog on June 9.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-25089
The second bug, CVE-2026-25089, was initially identified by Adham El Karn, a security researcher within the Fortinet Product Security team, and was disclosed by the cybersecurity firm on June 9.
June 16
Threat actors started abusing the Fortinet FortiSandbox and Microsoft SharePoint vulnerabilities in the wild.
Click on any entity below to view its context and source!
attribution
BleepingComputer
While Fortinet has yet to tag these two vulnerabilities as used in attacks, and has not yet replied to BleepingComputer's emails regarding in-the-wild exploitation, threat intelligence company Defused revealed on June 16 that attackers had started abusing them in the wild.
July 16
CISA added Fortinet's FortiSandbox and Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog on July 16.
Click on any entity below to view its context and source!
attribution
Known Exploited
CISA added both to
its Known Exploited Vulnerabilities (KEV) catalog
on July 16, suggesting evidence of observed exploitation in the wild.
tactic
T1588.006 - Vulnerabilities
CISA added both to
its Known Exploited Vulnerabilities (KEV) catalog
on July 16, suggesting evidence of observed exploitation in the wild.
attribution
KEV
CISA added both to
its Known Exploited Vulnerabilities (KEV) catalog
on July 16, suggesting evidence of observed exploitation in the wild.
April 14 and June 9
Threat actors exploited CVE-2026-25089 and CVE-2026-39808 vulnerabilities in Microsoft SharePoint.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-25089
These two critical-severity security flaws (tracked as
CVE-2026-39808
and
CVE-2026-25089
) were addressed by Fortinet on April 14 and June 9, respectively.
vulnerability
CVE-2026-39808
These two critical-severity security flaws (tracked as
CVE-2026-39808
and
CVE-2026-25089
) were addressed by Fortinet on April 14 and June 9, respectively.
2026/07/18
U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to prioritize patching two actively exploited vulnerabilities in Fortinet's FortiSandbox threat detection platform.
Click on any entity below to view its context and source!
organisation
CVSS
The vulnerabilities, tracked as CVE-2026-39808 and CVE-2026-25089 are both critical, with a severity rating (CVSS) of 9.1 each.
organisation
CVE-2026
The vulnerabilities, tracked as CVE-2026-39808 and CVE-2026-25089 are both critical, with a severity rating (CVSS) of 9.1 each.
organisation
Fortinet FortiSandbox
"We are observing exploitation of multiple Fortinet FortiSandbox vulnerabilities during the past 24 hours, including: CVE-2026-39813 (no previous recorded exploitation), CVE-2026-39808, CVE-2026-25089 (vibecoded, likely faulty exploit)," Defused
warned
.
organisation
FortiSandbox
Fortinet has released a patch in FortiSandbox version 4.4.9.
infrastructure
4.4.9
Fortinet has released a patch in FortiSandbox version 4.4.9.
Fortinet has released a patch in FortiSandbox versions 4.4.9 and 5.0.6.
organisation
Fortinet
In February, Fortinet also patched a critical SQL injection vulnerability (
CVE-2026-21643
) in the FortiClient Enterprise Management Server (EMS) platform, which Defused flagged
as actively exploited
one month later.
organisation
SQL
In February, Fortinet also patched a critical SQL injection vulnerability (
CVE-2026-21643
) in the FortiClient Enterprise Management Server (EMS) platform, which Defused flagged
as actively exploited
one month later.
organisation
the FortiClient Enterprise Management
In February, Fortinet also patched a critical SQL injection vulnerability (
CVE-2026-21643
) in the FortiClient Enterprise Management Server (EMS) platform, which Defused flagged
as actively exploited
one month later.
organisation
EMS
In February, Fortinet also patched a critical SQL injection vulnerability (
CVE-2026-21643
) in the FortiClient Enterprise Management Server (EMS) platform, which Defused flagged
as actively exploited
one month later.
organisation
Defused
In February, Fortinet also patched a critical SQL injection vulnerability (
CVE-2026-21643
) in the FortiClient Enterprise Management Server (EMS) platform, which Defused flagged
as actively exploited
one month later.
infrastructure
4.4.0
It is an operating system (OS) command injection vulnerability affecting Fortinet’s FortiSandbox versions 4.4.0 to 4.4.8.
It is an OS command injection vulnerability affecting Fortinet’s FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8 and all 4.2 versions, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5.
infrastructure
4.4.8
It is an operating system (OS) command injection vulnerability affecting Fortinet’s FortiSandbox versions 4.4.0 to 4.4.8.
It is an OS command injection vulnerability affecting Fortinet’s FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8 and all 4.2 versions, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5.
organisation
Fortinet’s FortiSandbox
It is an operating system (OS) command injection vulnerability affecting Fortinet’s FortiSandbox versions 4.4.0 to 4.4.8.
infrastructure
5.0.0
It is an OS command injection vulnerability affecting Fortinet’s FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8 and all 4.2 versions, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5.
infrastructure
5.0.5
It is an OS command injection vulnerability affecting Fortinet’s FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8 and all 4.2 versions, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5.
infrastructure
4.2
It is an OS command injection vulnerability affecting Fortinet’s FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8 and all 4.2 versions, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5.
infrastructure
5.0.4
It is an OS command injection vulnerability affecting Fortinet’s FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8 and all 4.2 versions, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5.
infrastructure
5.0.6
Fortinet has released a patch in FortiSandbox versions 4.4.9 and 5.0.6.
organisation
Shutterstock.com
Image credits: Piotr Swat / bluestork / Shutterstock.com
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
July 19, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to fix known exploited vulnerabilities in Fortinet's FortiSandbox software by July 19, 2026.
July 2026
Microsoft's July 2026 Patch Tuesday addressed the SharePoint remote code execution bug CVE-2026-58644.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-25089
CVE-2026-25089
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-39808
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-58644
(CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
This week,
Microsoft’s July 2026 Patch Tuesday
addressed the SharePoint remote code execution bug CVE-2026-58644, which can be triggered without authentication or user interaction.
vulnerability
CVE-2026-39808
CVE-2026-25089
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-39808
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-58644
(CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
This week,
Microsoft’s July 2026 Patch Tuesday
addressed the SharePoint remote code execution bug CVE-2026-58644, which can be triggered without authentication or user interaction.
vulnerability
CVE-2026-58644
CVE-2026-25089
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-39808
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-58644
(CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
This week,
Microsoft’s July 2026 Patch Tuesday
addressed the SharePoint remote code execution bug CVE-2026-58644, which can be triggered without authentication or user interaction.
vulnerability
CVSS score of 9.8
CVE-2026-25089
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-39808
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-58644
(CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
This week,
Microsoft’s July 2026 Patch Tuesday
addressed the SharePoint remote code execution bug CVE-2026-58644, which can be triggered without authentication or user interaction.
tactic
Remote Code Execution
CVE-2026-25089
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-39808
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-58644
(CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
This week,
Microsoft’s July 2026 Patch Tuesday
addressed the SharePoint remote code execution bug CVE-2026-58644, which can be triggered without authentication or user interaction.
organisation
CVSS
CVE-2026-25089
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-39808
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-58644
(CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
This week,
Microsoft’s July 2026 Patch Tuesday
addressed the SharePoint remote code execution bug CVE-2026-58644, which can be triggered without authentication or user interaction.
organisation
Microsoft
CVE-2026-25089
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-39808
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-58644
(CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
This week,
Microsoft’s July 2026 Patch Tuesday
addressed the SharePoint remote code execution bug CVE-2026-58644, which can be triggered without authentication or user interaction.
organisation
SharePoint
CVE-2026-25089
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-39808
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-58644
(CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
This week,
Microsoft’s July 2026 Patch Tuesday
addressed the SharePoint remote code execution bug CVE-2026-58644, which can be triggered without authentication or user interaction.
organisation
CVE-2026
CVE-2026-25089
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-39808
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-58644
(CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
This week,
Microsoft’s July 2026 Patch Tuesday
addressed the SharePoint remote code execution bug CVE-2026-58644, which can be triggered without authentication or user interaction.
general_metric
58644 CVE-2026
CVE-2026-25089
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-39808
(CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-58644
(CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
This week,
Microsoft’s July 2026 Patch Tuesday
addressed the SharePoint remote code execution bug CVE-2026-58644, which can be triggered without authentication or user interaction.
organisation
KeV
The second issue added to the KeV catalog is an OS command injection flaw, tracked as
CVE-2026-25089
, in FortiSandbox products.
organisation
FortiSandbox
The second issue added to the KeV catalog is an OS command injection flaw, tracked as
CVE-2026-25089
, in FortiSandbox products.
infrastructure
Microsoft Office
“Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.”
reads the advisory
.
organisation
Microsoft Office SharePoint
“Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.”
reads the advisory
.
July 19
The U.S. CISA added Fortinet FortiSandbox and Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog, prompting a July 19 deadline for federal government agencies to roll out patches.
Click on any entity below to view its context and source!
industry
Government
The agency urged rolling out patches across federal government by July 19.
Sunday, July 19
Threat actors exploited vulnerabilities in Fortinet's FortiSandbox and Microsoft SharePoint to target U.S. federal agencies, with patches required by July 19.
Click on any entity below to view its context and source!
attribution
FortiSandbox
As mandated by Binding Operational Directive (BOD) 26-04, U.S. federal agencies must patch vulnerable FortiSandbox instances by Sunday, July 19.
general_metric
26 Binding Operational Directive
As mandated by Binding Operational Directive (BOD) 26-04, U.S. federal agencies must patch vulnerable FortiSandbox instances by Sunday, July 19.
Tactical Metrics
Metrics
infrastructure
Microsoft Office
Affected Product
Click for context!
“Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.”
reads the advisory
.
Metrics
infrastructure
4.4.0
Software Version
It is an operating system (OS) command injection vulnerability affecting Fortinet’s FortiSandbox versions 4.4.0 to 4.4.8.
It is an OS command injection vulnerability affecting Fortinet’s FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8 and all 4.2 versions, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5.
Metrics
infrastructure
4.4.8
Software Version
It is an operating system (OS) command injection vulnerability affecting Fortinet’s FortiSandbox versions 4.4.0 to 4.4.8.
It is an OS command injection vulnerability affecting Fortinet’s FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8 and all 4.2 versions, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5.
Metrics
infrastructure
4.4.9
Software Version
Fortinet has released a patch in FortiSandbox version 4.4.9.
Fortinet has released a patch in FortiSandbox versions 4.4.9 and 5.0.6.
Metrics
infrastructure
5.0.0
Software Version
It is an OS command injection vulnerability affecting Fortinet’s FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8 and all 4.2 versions, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5.
Metrics
infrastructure
5.0.5
Software Version
It is an OS command injection vulnerability affecting Fortinet’s FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8 and all 4.2 versions, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5.
Metrics
infrastructure
4.2
Software Version
It is an OS command injection vulnerability affecting Fortinet’s FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8 and all 4.2 versions, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5.
Metrics
infrastructure
5.0.4
Software Version
It is an OS command injection vulnerability affecting Fortinet’s FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8 and all 4.2 versions, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5.
Metrics
infrastructure
5.0.6
Software Version
Fortinet has released a patch in FortiSandbox versions 4.4.9 and 5.0.6.
Intelligence Sources
BleepingComputer
2026-07-17
CISA urges immediate action on actively exploited Fortinet flaws
BleepingComputer
Security Affairs
2026-07-18
Infosecurity-Magazine
2026-07-17
CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-19T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
19x
organisation
Identified Entity
CVSS
entity
13x
attribution
Attributing Entity
Microsoft SharePoint
authority
11x
timeline
Temporal Reference
July 19, 2026
date
8x
infrastructure
Software Version
4.4.0
version
6x
vulnerability
Exploited CVE
CVE-2026-25089
cve
3x
tactic
Cyber Operation Type
Remote Code Execution
tactic
3x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
general metric
Cve-2026
58,644
cve-2026
2x
target region
Target Country
Spain
country
2x
general metric
%
54
%
Contextual Telemetry
Context Block
9 METRICS
vulnerability
CVSS Score
10
score
infrastructure
Affected Product
Microsoft Office
software
general metric
Hour
24
hour
source region
Origin Country
United States
country
industry
Targeted Sector
Government
sector
general metric
Versions
4
versions
general metric
Tracks Fortinet Vulnerabilities
28
tracks fortinet vulnerabilities
general metric
Years
13
years
general metric
Binding Operational Directive
26
binding operational directive
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.