Fortinet FortiSandbox CVEs enter CISA KEV with July 19 deadline
CISA added two Fortinet FortiSandbox command-injection flaws to KEV on July 16, with a July 19 remediation deadline for covered agencies and urgent patch priority for exposed appliances.
CISA has moved two Fortinet FortiSandbox command-injection vulnerabilities into the Known Exploited Vulnerabilities catalog and set July 19, 2026 as the remediation due date for covered federal systems. The entries are CVE-2026-25089 and CVE-2026-39808, both marked by NVD with network attack vectors, no required privileges, no user interaction, and high confidentiality, integrity, and availability impact.
For operators, the timing matters more than the age of the original advisories. FortiSandbox is a trusted security appliance that receives hostile files and URLs by design. Once exploitation is confirmed, an exposed management surface becomes a high-value pivot point rather than a routine patch item.
CISA's July 19 FortiSandbox clock
The official KEV feed lists CVE-2026-25089 and CVE-2026-39808 as added on July 16, 2026, with remediation due July 19, 2026. CISA's required action is to apply vendor mitigations under its risk-based patching guidance, follow forensics triage requirements where applicable, and discontinue use if mitigations are unavailable.
That deadline is mandatory for U.S. federal civilian agencies under CISA's binding directives. It is also a useful risk signal for private organizations because KEV inclusion means exploitation has moved beyond theoretical proof-of-concept status.
What CVE-2026-25089 and CVE-2026-39808 affect
NVD describes CVE-2026-25089 as improper neutralization of OS command elements in Fortinet FortiSandbox. The affected range spans FortiSandbox 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, the 4.2 line, plus FortiSandbox Cloud and FortiSandbox PaaS 5.0.4 through 5.0.5.
CVE-2026-39808 is also an OS command-injection issue. NVD lists FortiSandbox 4.4.0 through 4.4.8 as affected, with FortiSandbox PaaS versions also represented in the affected configuration data. Both NVD pages reference Fortinet's PSIRT advisories, so teams should use the Fortinet notices as the source of truth for fixed versions and supported upgrade paths.
Exploitation signals are already public
CrowdSec says it observed exploitation attempts for CVE-2026-39808 beginning June 17, 2026 and tracked 49 malicious IP addresses probing the issue at publication time. Its writeup also notes a public proof of concept and Nuclei detection template, which lowers the threshold for broader scanning.
The practical takeaway is straightforward: do not wait for your vulnerability scanner's normal maintenance cycle if the appliance is reachable from untrusted networks. The public exploit and KEV status are enough to move this from a backlog item to an emergency exposure check.
Triage steps for FortiSandbox owners
Start with an inventory pass: locate all FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS deployments, then confirm whether their management interfaces are internet-exposed or reachable from partner networks. Treat externally reachable systems as the first patch wave.
Apply Fortinet's fixed releases or mitigations for FG-IR-26-141 and FG-IR-26-100. If a system cannot be upgraded immediately, restrict management access, place compensating controls in front of the interface, and look for evidence of command execution attempts or unusual files created through web endpoints.
For teams already using vulnerability management, map the CVEs directly rather than relying only on product names. CVE-2026-25089 and CVE-2026-39808 overlap in product family but do not have identical affected-version scopes.
Evidence
This post uses CISA's machine-readable KEV feed as the primary source, NVD's CVE records for affected-version and impact data, Fortinet PSIRT advisory URLs referenced by NVD, and independent exploitation context from CrowdSec. Security teams should verify final remediation details against Fortinet's live advisories before making production changes.
