CISA Orders Immediate Patch for Actively Exploited FortiSandbox Vulnerabilities (CVE‑2026‑39808, CVE‑2026‑25089)
What Happened — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a Binding Operational Directive requiring federal agencies to patch two critical Fortinet FortiSandbox flaws (CVE‑2026‑39808 and CVE‑2026‑25089) that are being actively exploited in the wild via unauthenticated command‑injection attacks. Fortinet released fixes in April and June 2024, but threat‑intel firm Defused observed exploitation as early as June 16.
Why It Matters for Compliance & Audit Readiness
- Unpatched code‑execution flaws constitute a direct violation of SOC 2 CC6 (System Operations) and CC7 (Change Management) controls that demand timely remediation of known vulnerabilities.
- Continuous evidence of patch status and remediation timelines is essential audit evidence; Verisq’s control‑mapping capability automates collection of patch‑management logs to demonstrate compliance.
Who Is Affected – Enterprises that deploy FortiSandbox for threat detection across sectors such as technology, finance, healthcare, and government.
Recommended Actions –
- Verify FortiSandbox version against Fortinet’s advisory and apply the latest patches immediately.
- Capture patch‑deployment logs and map them to SOC 2 change‑management controls.
- Update your vulnerability‑management policy to include “active‑exploitation” triggers and enforce a 48‑hour remediation window for critical findings.
Source: BleepingComputer
Technical Notes – Both CVEs are unauthenticated command‑injection bugs (remote code execution) with CVSS ≥ 9.8. No user interaction is required. Fortinet also disclosed a related SQL‑injection flaw (CVE‑2026‑21643) and a path‑traversal issue (CVE‑2025‑61624) in the same product line. Source: Fortinet security advisories