HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

CISA Orders Immediate Patch for Actively Exploited FortiSandbox Vulnerabilities (CVE‑2026‑39808, CVE‑2026‑25089)

CISA issued a binding directive forcing federal agencies to patch two critical FortiSandbox flaws that are being exploited in the wild. The vulnerabilities allow unauthenticated remote code execution, making timely remediation a SOC 2 control requirement.

LiveThreat™ Intelligence · 📅 July 17, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

CISA Orders Immediate Patch for Actively Exploited FortiSandbox Vulnerabilities (CVE‑2026‑39808, CVE‑2026‑25089)

What Happened — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a Binding Operational Directive requiring federal agencies to patch two critical Fortinet FortiSandbox flaws (CVE‑2026‑39808 and CVE‑2026‑25089) that are being actively exploited in the wild via unauthenticated command‑injection attacks. Fortinet released fixes in April and June 2024, but threat‑intel firm Defused observed exploitation as early as June 16.

Why It Matters for Compliance & Audit Readiness

  • Unpatched code‑execution flaws constitute a direct violation of SOC 2 CC6 (System Operations) and CC7 (Change Management) controls that demand timely remediation of known vulnerabilities.
  • Continuous evidence of patch status and remediation timelines is essential audit evidence; Verisq’s control‑mapping capability automates collection of patch‑management logs to demonstrate compliance.

Who Is Affected – Enterprises that deploy FortiSandbox for threat detection across sectors such as technology, finance, healthcare, and government.

Recommended Actions

  • Verify FortiSandbox version against Fortinet’s advisory and apply the latest patches immediately.
  • Capture patch‑deployment logs and map them to SOC 2 change‑management controls.
  • Update your vulnerability‑management policy to include “active‑exploitation” triggers and enforce a 48‑hour remediation window for critical findings.

Source: BleepingComputer

Technical Notes – Both CVEs are unauthenticated command‑injection bugs (remote code execution) with CVSS ≥ 9.8. No user interaction is required. Fortinet also disclosed a related SQL‑injection flaw (CVE‑2026‑21643) and a path‑traversal issue (CVE‑2025‑61624) in the same product line. Source: Fortinet security advisories

📰 Original Source
https://www.bleepingcomputer.com/news/security/cisa-warns-feds-to-patch-exploited-fortinet-fortisandbox-flaws-by-sunday/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →