
CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands
The Cybersecurity and Infrastructure Security Agency (CISA) added two Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on July 16, 2026, confirming active exploitation of both flaws in the wild. Both vulnerabilities, tracked as CVE-2026-39808 and CVE-2026-25089, share a common root cause: OS command injection (CWE-78). This class of vulnerability arises when an […]
The post CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands appeared first on Cyber Security News.