CISA urges immediate action on actively exploited Fortinet flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to government agencies to take immediate action against two critical security vulnerabilities in Fortinet’s threat detection platform, FortiSandbox. These flaws have been actively exploited by attackers in the wild, allowing unauthorized code execution through low-complexity command injection attacks. The good news is that patches were released by Fortinet back in April and June, but the bad news is that many organizations are still vulnerable.

The two critical-severity vulnerabilities, tracked as CVE-2026-39808 and CVE-2026-25089, can be exploited remotely with no user interaction required. This means that attackers can launch attacks without needing to trick users into clicking on a malicious link or opening an attachment. To resolve these issues, admins must upgrade all affected deployments to the latest released versions as soon as possible.

CISA’s warning is not just limited to government agencies; it applies to any organization using FortiSandbox. The agency has confirmed that attackers are actively exploiting these flaws in the wild, and threat intelligence company Defuse revealed on June 16 that they had started abusing them in attacks. It’s worth noting that while Fortinet hasn’t yet confirmed the exploitation of these vulnerabilities, CISA’s warning is based on credible reports from trusted sources.

The FortiSandbox platform is a threat detection solution designed to identify and contain potential security threats. However, it appears that attackers are using these vulnerabilities to bypass its defenses and launch attacks. This highlights the importance of regularly updating and patching critical systems like FortiSandbox to prevent exploitation.

Fortinet has faced several high-profile vulnerability disclosures in recent years, with many of them being exploited by attackers. CISA tracks 28 Fortinet vulnerabilities that have been used in attacks, with 13 of those also being abused in ransomware attacks. It’s clear that the company needs to prioritize patching and disclosure to prevent further exploitation.

The takeaway from this story is that organizations using FortiSandbox must take immediate action to patch these vulnerabilities. CISA has given government agencies a deadline of July 19 to resolve the issue, but private sector organizations should also treat this as a high-priority task. Regularly updating systems and monitoring for potential threats can help prevent attacks like these from succeeding.


Source: Bleeping Computer — 2026-07-17