highZero-Day

CISA KEV Catalog Update: Fortinet FortiSandbox and Microsoft SharePoint Actively Exploited Vulnerabilities

First seen Jul 17, 2026 · Updated Jul 17, 2026

kev-catalogfortinetfortisandboxmicrosoft-sharepointos-command-injectiondeserializationactive-exploitationfcebbod-26-04agent-relevant

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: two OS command injection flaws in Fortinet FortiSandbox and a deserialization of untrusted data vulnerability in Microsoft SharePoint. All three are confirmed to be exploited in the wild and pose significant risk to organizations running these products, particularly federal agencies bound by BOD 26-04 remediation timelines.

Technical Analysis

CVE-2026-25089 and CVE-2026-39808 are OS command injection vulnerabilities in Fortinet FortiSandbox, which could allow an authenticated or unauthenticated attacker to execute arbitrary system commands on the underlying host, potentially leading to full device compromise. CVE-2026-58644 is a deserialization of untrusted data vulnerability in Microsoft SharePoint, a class of bug historically leveraged for remote code execution by crafting malicious serialized objects that execute upon deserialization by the server. All three vulnerabilities have confirmed evidence of active exploitation per CISA's KEV inclusion criteria, indicating they are being used in real-world attack campaigns rather than theoretical risk. Organizations that host SharePoint-integrated RAG pipelines, internal knowledge bases, or agent orchestration tools connected to SharePoint document repositories should treat this as a direct risk, since RCE on the SharePoint server could expose stored API keys, service account credentials, or documents used to ground LLM agents, and a compromised FortiSandbox appliance sitting in the security stack could allow attackers to pivot toward internal systems hosting agent infrastructure.

Affected Systems

Fortinet FortiSandbox (versions affected by CVE-2026-25089 and CVE-2026-39808 - consult Fortinet PSIRT advisories for exact version ranges); Microsoft SharePoint Server (on-premises deployments affected by CVE-2026-58644 - consult Microsoft Security Response Center advisory for exact version ranges)

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) published in this CISA alert; organizations should consult vendor advisories (Fortinet PSIRT, Microsoft MSRC) and CISA KEV catalog entries for exploitation indicators as they become available

Remediation Steps

  1. 1

    Apply vendor patches immediately

    Update FortiSandbox to the patched version specified in the Fortinet PSIRT advisory for CVE-2026-25089 and CVE-2026-39808, and apply the Microsoft security update addressing CVE-2026-58644 in SharePoint Server.

  2. 2

    Follow BOD 26-04 requirements

    FCEB agencies must remediate these KEV-listed vulnerabilities within CISA's mandated timelines and check for signs of compromise predating the patch, per BOD 26-04 guidance.

  3. 3

    Audit for prior compromise

    Review logs on affected FortiSandbox and SharePoint systems for signs of exploitation prior to patching, including unusual command execution, unexpected process spawning, or anomalous deserialization activity.

  4. 4

    Restrict public exposure

    Limit or eliminate public internet exposure of FortiSandbox management interfaces and SharePoint servers where possible, and enforce network segmentation and access controls.

  5. 5

    Rotate credentials tied to SharePoint-integrated services

    If SharePoint is integrated with agent frameworks, RAG pipelines, or automation tools, rotate any API keys, service account credentials, or tokens stored in or accessible via SharePoint following patch deployment.

  6. 6

    Monitor CISA KEV catalog

    Continuously track the KEV catalog for updates and integrate it into vulnerability management prioritization processes.

CVE / Advisory IDs

CVE-2026-25089CVE-2026-39808CVE-2026-58644

Industries Most Exposed

governmentfederal civilian executive branchtechnologyfinancial serviceshealthcarecritical infrastructureall sectors using Fortinet or Microsoft SharePoint

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.