CISA Adds Critical FortiSandbox and SharePoint RCE Flaws to Known Exploited Vulnerabilities Catalog
What Happened — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) placed three high‑severity vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog: two Fortinet FortiSandbox OS command‑injection bugs (CVE‑2026‑25089 and CVE‑2026‑39808) and a Microsoft SharePoint deserialization remote‑code‑execution flaw (CVE‑2026‑58644). All three carry a CVSS 9.8 score and have been observed in active exploitation.
Why It Matters for Compliance & Audit Readiness
- These flaws expose a control gap in the “System Operations” and “Change Management” domains that SOC 2‑compliant programs must identify, remediate, and continuously monitor.
- Mapping remediation to SOC 2 controls provides defensible audit evidence that the organization is actively addressing known‑exploited risks.
- Continuous evidence collection (e.g., patch‑status logs, vulnerability scans) satisfies the audit‑ready documentation required for the “Risk Management” principle.
Who Is Affected — Enterprises that deploy Fortinet FortiSandbox appliances and organizations running Microsoft SharePoint (on‑premises or cloud‑based).
Recommended Actions —
- Deploy the vendor‑issued patches for FortiSandbox and SharePoint without delay.
- Prioritize these CVEs in your vulnerability‑management workflow and record remediation steps in your SOC 2 evidence repository.
- Align the remediation effort with SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) controls, and capture continuous monitoring data for audit reviewers.
Technical Notes —
- CVE‑2026‑25089 & CVE‑2026‑39808 (FortiSandbox) – OS command injection (CWE‑78); unauthenticated HTTP requests can execute arbitrary commands.
- CVE‑2026‑58644 (Microsoft SharePoint) – Deserialization of untrusted data; can be triggered without authentication or user interaction, allowing remote code execution.
- All three vulnerabilities have a CVSS 9.8 rating. Source: Security Affairs