CISA urges immediate action on actively exploited Fortinet flaws

A critical vulnerability in Fortinet’s threat detection platform has been exploited by attackers, prompting a warning from the US Cybersecurity and Infrastructure Security Agency (CISA) that government agencies must take immediate action to patch the flaw. The affected vulnerability, one of two actively exploited issues in the FortiSandbox platform, was addressed by Fortinet on April 14 but remains unpatched in many systems.

The flaws, tracked as CVE-2026-39808 and CVE-2026-25089, allow unauthenticated threat actors to execute unauthorized code remotely through low-complexity command injection attacks that require no user interaction. While Fortinet has not yet confirmed the exploitation of these vulnerabilities in the wild, threat intelligence company Defused revealed on June 16 that attackers had begun abusing them in attacks. CISA’s confirmation of active exploitation adds these flaws to its catalog of known exploited vulnerabilities.

The urgency of this issue is underscored by the fact that CISA has mandated that US federal agencies must patch vulnerable FortiSandbox instances by Sunday, July 19. This directive is in line with Binding Operational Directive (BOD) 26-04, which requires federal agencies to prioritize patching of known exploited vulnerabilities. The rapid response from CISA highlights the severity of this issue and the potential for significant harm if left unaddressed.

The Fortinet FortiSandbox platform is widely used by organizations around the world, and the exploitation of these vulnerabilities could have far-reaching consequences. In recent years, Fortinet vulnerabilities have been exploited in numerous cyber espionage campaigns and ransomware attacks. According to CISA, 28 Fortinet vulnerabilities have been exploited in attacks, with 13 of those also being abused in ransomware attacks.

The pace at which attackers are exploiting known vulnerabilities is alarming, and the need for rapid patching cannot be overstated. Organizations must prioritize the security of their systems and take immediate action to address these issues. This includes upgrading all affected deployments to the latest released versions of FortiSandbox to block incoming attacks.

In practical terms, this means that system administrators must carefully review their FortiSandbox configurations and ensure that they are running the latest version of the software. Regularly scheduled security updates and patching cycles can help identify and address vulnerabilities before attackers have a chance to exploit them. By taking proactive steps to secure their systems, organizations can reduce the risk of successful attacks and minimize the potential for harm.


Source: Bleeping Computer — 2026-07-17