Executive Summary
On July 16, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. The vulnerabilities include two OS command injection flaws in Fortinet FortiSandbox (CVE-2026-25089 and CVE-2026-39808) and a deserialization of untrusted data vulnerability in Microsoft SharePoint (CVE-2026-58644). These vulnerabilities are commonly exploited by malicious actors and pose significant risks to federal enterprises.
The inclusion of these vulnerabilities in the KEV Catalog underscores the critical need for organizations to prioritize patching and remediation efforts. With the increasing frequency of such exploits, it is imperative for entities to adopt risk-based vulnerability management practices to safeguard their systems against potential breaches.
Why This Matters Now
The active exploitation of these vulnerabilities highlights the urgency for organizations to implement timely security updates and adhere to CISA's directives to mitigate potential threats.
Attack Path Analysis
Attackers exploited OS command injection vulnerabilities in FortiSandbox to gain unauthorized access. They escalated privileges to execute arbitrary commands with root access. The attackers moved laterally within the network, compromising additional systems. They established command and control channels to maintain persistent access. Sensitive data was exfiltrated from the compromised systems. The attack resulted in significant operational disruption and potential data loss.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited OS command injection vulnerabilities in FortiSandbox to gain unauthorized access.
Related CVEs
CVE-2026-25089
CVSS 9.8An OS command injection vulnerability in Fortinet FortiSandbox versions 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, 4.2 (all versions), FortiSandbox Cloud versions 5.0.4 through 5.0.5, and FortiSandbox PaaS versions 5.0.4 through 5.0.5 allows unauthenticated attackers to execute unauthorized commands via specifically crafted HTTP requests.
Affected Products:
Fortinet FortiSandbox – 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, 4.2 (all versions)
Fortinet FortiSandbox Cloud – 5.0.4 through 5.0.5
Fortinet FortiSandbox PaaS – 5.0.4 through 5.0.5
Exploit Status:
exploited in the wildCVE-2026-39808
CVSS 9.8An OS command injection vulnerability in Fortinet FortiSandbox versions 4.4.0 through 4.4.8 allows attackers to execute unauthorized code or commands via a specific attack vector.
Affected Products:
Fortinet FortiSandbox – 4.4.0 through 4.4.8
Exploit Status:
exploited in the wildCVE-2026-58644
CVSS 9.8Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Affected Products:
Microsoft SharePoint Server 2019 – up to 16.0.10417.20153
Microsoft SharePoint Server 2016 – up to 16.0.5556.1005
Microsoft SharePoint Server Subscription Edition – up to 16.0.19725.20384
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Client Execution
Command and Scripting Interpreter
Valid Accounts
Abuse Elevation Control Mechanism
Application Layer Protocol
OS Credential Dumping
Remote Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face critical vulnerability exploitation risks in Fortinet FortiSandbox and Microsoft SharePoint, requiring immediate remediation under BOD 26-04 compliance mandates.
Financial Services
Banking institutions vulnerable to OS command injection and deserialization attacks through widely-deployed Fortinet security appliances and SharePoint collaboration platforms in hybrid environments.
Health Care / Life Sciences
Healthcare organizations risk HIPAA compliance violations from SharePoint deserialization vulnerabilities and FortiSandbox exploitation enabling lateral movement through encrypted patient data systems.
Computer Software/Engineering
Software companies face heightened risks from vulnerability exploitation affecting development environments, particularly SharePoint-based collaboration tools and Fortinet security infrastructure protecting intellectual property.
Sources
- CISA Adds Three Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalogVerified
- Fortinet Security Advisory FG-IR-26-100https://fortiguard.fortinet.com/psirt/FG-IR-26-100Verified
- Microsoft Security Update Guide - CVE-2026-58644https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been limited to the compromised workload, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: Even with escalated privileges, the attacker's ability to access other workloads would likely have been constrained.
Control: East-West Traffic Security
Mitigation: Lateral movement could have been restricted, reducing the number of systems the attacker could compromise.
Control: Multicloud Visibility & Control
Mitigation: Establishing command and control channels may have been detected and disrupted, limiting persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts could have been identified and blocked, reducing the risk of data loss.
Operational disruption and data loss may have been minimized due to constrained attacker movement and data exfiltration.
Impact at a Glance
Affected Business Functions
- Network Security Monitoring
- Email Filtering
- File Analysis
- Collaboration Platforms
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive corporate communications and documents.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation of known vulnerabilities.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to suspicious activities.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Ensure timely patching of vulnerabilities to mitigate potential exploitation risks.



