HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

CISA Adds Critical FortiSandbox and SharePoint RCE Flaws to Known Exploited Vulnerabilities Catalog

CISA placed two FortiSandbox OS command injection CVEs (CVE‑2026‑25089, CVE‑2026‑39808) and a SharePoint deserialization RCE CVE (CVE‑2026‑58644) into its KEV catalog, each scoring 9.8 and confirmed as actively exploited. Organizations must treat these as high‑priority control gaps, mapping remediation to SOC 2 audit evidence.

LiveThreat™ Intelligence · 📅 July 18, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

CISA Adds Critical FortiSandbox and SharePoint RCE Flaws to Known Exploited Vulnerabilities Catalog

What Happened — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) placed three high‑severity vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog: two Fortinet FortiSandbox OS command‑injection bugs (CVE‑2026‑25089 and CVE‑2026‑39808) and a Microsoft SharePoint deserialization remote‑code‑execution flaw (CVE‑2026‑58644). All three carry a CVSS 9.8 score and have been observed in active exploitation.

Why It Matters for Compliance & Audit Readiness

  • These flaws expose a control gap in the “System Operations” and “Change Management” domains that SOC 2‑compliant programs must identify, remediate, and continuously monitor.
  • Mapping remediation to SOC 2 controls provides defensible audit evidence that the organization is actively addressing known‑exploited risks.
  • Continuous evidence collection (e.g., patch‑status logs, vulnerability scans) satisfies the audit‑ready documentation required for the “Risk Management” principle.

Who Is Affected — Enterprises that deploy Fortinet FortiSandbox appliances and organizations running Microsoft SharePoint (on‑premises or cloud‑based).

Recommended Actions

  • Deploy the vendor‑issued patches for FortiSandbox and SharePoint without delay.
  • Prioritize these CVEs in your vulnerability‑management workflow and record remediation steps in your SOC 2 evidence repository.
  • Align the remediation effort with SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) controls, and capture continuous monitoring data for audit reviewers.

Technical Notes

  • CVE‑2026‑25089 & CVE‑2026‑39808 (FortiSandbox) – OS command injection (CWE‑78); unauthenticated HTTP requests can execute arbitrary commands.
  • CVE‑2026‑58644 (Microsoft SharePoint) – Deserialization of untrusted data; can be triggered without authentication or user interaction, allowing remote code execution.
  • All three vulnerabilities have a CVSS 9.8 rating. Source: Security Affairs
📰 Original Source
https://securityaffairs.com/195569/security/u-s-cisa-adds-fortinet-fortisandbox-and-microsoft-sharepoint-flaws-to-its-known-exploited-vulnerabilities-catalog.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →