The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to address them by July 19, 2026. The newly listed flaws include one affecting Microsoft SharePoint and two impacting Fortinet FortiSandbox products.
The Microsoft SharePoint vulnerability, tracked as CVE-2026-58644, is a deserialization of untrusted data flaw with a CVSS score of 9.8. This remote code execution bug can be triggered without authentication or user interaction. Microsoft confirmed active exploitation of this vulnerability, which was addressed in its July 2026 Patch Tuesday updates. The flaw allows an attacker, authenticated as at least a Site Owner, to execute arbitrary code remotely on a SharePoint Server by injecting specially crafted code.
For Fortinet FortiSandbox, CISA added two OS command injection vulnerabilities: CVE-2026-25089 and CVE-2026-39808, both also carrying a CVSS score of 9.8. These flaws could allow remote, unauthenticated attackers to execute unauthorized commands or code on affected devices by sending specially crafted HTTP requests. Fortinet’s Product Security team member Adham El Karn discovered CVE-2026-25089. Cybersecurity firm Defused Cyber reported observing active exploitation of one of these FortiSandbox vulnerabilities within a 24-hour period.
Under CISA's Binding Operational Directive (BOD) 22-01, federal civilian executive branch (FCEB) agencies are mandated to remediate vulnerabilities listed in the KEV catalog by specified due dates to protect their networks. CISA also advises private organizations to review the catalog and address these vulnerabilities within their own infrastructures.






