CISA Adds Actively Exploited Fortinet FortiSandbox Flaw to KEV Catalog
CISA has confirmed active exploitation of an OS command injection vulnerability in Fortinet FortiSandbox, mandating urgent remediation for federal agencies.
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS are affected by an OS command injection vulnerability, tracked as CVE-2026-25089. This security flaw, categorized as CWE-78, allows an unauthenticated attacker to execute unauthorized commands on the system by sending specifically crafted HTTP requests.
The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog as of July 16, 2026, confirming its use in real-world attacks. Federal agencies are required to apply necessary mitigations by July 19, 2026, in accordance with BOD 26-04 guidelines.
Organizations are advised to follow vendor instructions to secure their deployments. Stakeholders must evaluate the internet exposure of their assets and ensure compliance with CISA's forensics triage requirements and patching guidance. If mitigations are unavailable for cloud services, agencies should discontinue use of the product.
Sources
- CISA KEV Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.