FortiSandbox: CVE-2026-25089 and CVE-2026-39808 land in KEV, exploited
CISA added two critical unauthenticated OS command injection flaws in Fortinet FortiSandbox to KEV on July 16, 2026. BOD 26-04 gave FCEB agencies until July 19 to patch. Both are CVSS 9.1.