CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on 16 July 2026: two OS command injection flaws in Fortinet FortiSandbox and one deserialization flaw in Microsoft SharePoint. All three carry a 19 July remediation deadline. For all three, the KEV field for known ransomware campaign use reads Unknown.
Juan Ricardo Palacio
Co-Founder and CEO for the Americas, HelpRansomware
Electronic engineer and Co-Founder of HelpRansomware, with 25+ years in cybersecurity, digital forensics and ransomware incident response.
Three days. That is the entire distance between a vulnerability appearing on CISA’s Known Exploited Vulnerabilities catalog on 16 July 2026 and the date by which federal agencies must have it fixed. In April, the same catalog gave fourteen.
CISA added three actively exploited vulnerabilities to the KEV catalog on 16 July 2026, all with a remediation deadline of 19 July. Two affect Fortinet FortiSandbox (CVE-2026-25089 and CVE-2026-39808, both OS command injection reachable without authentication). One affects Microsoft SharePoint (CVE-2026-58644, deserialization of untrusted data leading to remote code execution). The catalog now lists 1,647 entries.
Read the KEV metadata before you read the headlines
For CVE-2026-25089, CVE-2026-39808 and CVE-2026-58644 the KEV field knownRansomwareCampaignUse reads Unknown. That is the catalog stating it has no evidence tying these flaws to a ransomware campaign. Treat them as what the record supports: actively exploited remote code execution on exposed infrastructure. Nothing in the KEV entry justifies a ransomware label, and the absence of that label does not lower the urgency of the deadline.
What CISA published on 16 July 2026
The three entries added to the catalog, as recorded in the KEV JSON:
- CVE-2026-25089, Fortinet FortiSandbox OS Command Injection Vulnerability. FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS contain an OS command injection flaw that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Vendor advisory FG-IR-26-141.
- CVE-2026-39808, Fortinet FortiSandbox OS Command Injection Vulnerability. FortiSandbox contains an OS command injection flaw that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. Vendor advisory FG-IR-26-100.
- CVE-2026-58644, Microsoft SharePoint Deserialization of Untrusted Data Vulnerability. SharePoint contains a deserialization of untrusted data flaw that allows an unauthorized attacker to execute code over a network.
- All three were added on 16 July 2026 with a due date of 19 July 2026.
- The required action for all three is to apply vendor mitigations in line with CISA Binding Operational Directive 26-04 and the Forensics Triage Requirements, or discontinue use of the product if mitigations are unavailable.
The 16 July KEV batch in numbers
All figures are read directly from the CISA Known Exploited Vulnerabilities JSON catalog, version 2026.07.16. The catalog is the authoritative record for dateAdded, dueDate, requiredAction and knownRansomwareCampaignUse. No third party interpretation is included in the numbers above.
What the catalog actually requires
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.
How the patch window closed
The interesting figure in this batch is not the CVSS score. It is the gap between dateAdded and dueDate, and how that gap has changed across 2026 as CISA moved from BOD 22-01 to BOD 26-04. For the wider pattern, see how a ransomware attack usually unfolds.
Days between KEV listing and deadline
The remediation window narrowed from fourteen days to three
CISA KEV JSON catalog, version 2026.07.16
Controls that match these specific entries
The controls below map to what the KEV entries actually describe, which is unauthenticated remote code execution against a security appliance and a collaboration server. They are not a generic hardening list.
| Control | Why it matters for this KEV batch | Gap it closes |
|---|---|---|
| Inventory of internet facing appliances | Both FortiSandbox entries describe an unauthenticated attacker reaching the product over crafted HTTP requests | Appliances nobody owns because they are considered security tooling |
| Three day patch SLA for KEV entries | The required action ties remediation to BOD 26-04 deadlines, which in this batch is 19 July | Patch cycles measured in weeks against a catalog measured in days |
| Vendor advisory subscription | The KEV notes point to FG-IR-26-141 and FG-IR-26-100 for the mitigation detail | Waiting for press coverage instead of the PSIRT advisory |
| Forensic triage readiness | The required action explicitly cites CISA Forensics Triage Requirements alongside patching | Patching an exploited box and destroying the evidence of whether it was already used |
| Decommission path | The required action allows discontinuing use of the product if mitigations are unavailable | No plan for an appliance that cannot be patched in time |
Where this goes wrong in practice
The failure modes below are not hypothetical risks. They follow directly from the structure of the KEV entries in this batch.
- ⛔ Treating a security appliance as infrastructure that protects rather than infrastructure that is exposed. FortiSandbox is reachable over HTTP in both entries.
- ⛔ Reading a KEV listing as a ransomware warning. The catalog records Unknown for ransomware campaign use on all three entries, and inventing that link is a reporting error, not a precaution.
- ⛔ Planning remediation on a monthly cycle when the catalog issues three day deadlines.
- ⛔ Patching first and triaging never, when the required action names forensic triage as part of the obligation.
- ⛔ Assuming the deadline only binds federal agencies, and therefore ignoring that the deadline exists because exploitation is already confirmed.
Patching does not tell you whether you were already reached
A KEV entry means exploitation has been observed somewhere, before the deadline was set. Applying the vendor fix closes the door but says nothing about who walked through it first. That is precisely why the required action for these three entries pairs mitigation with the CISA Forensics Triage Requirements rather than listing patching alone.
What to do before 19 July
None of the following needs a new budget line. They follow the required action recorded in the KEV entries themselves, in the order that reduces exposure fastest. For the full checklist, see our guide on preventing a ransomware attack.
- ✅ Confirm whether FortiSandbox, FortiSandbox Cloud or FortiSandbox PaaS is deployed anywhere in the estate, including instances owned by the security team rather than IT.
- ✅ Apply the mitigations in Fortinet advisories FG-IR-26-141 and FG-IR-26-100, and the Microsoft update guide entry for CVE-2026-58644.
- ✅ Check whether the SharePoint entries added on 1 and 14 July, CVE-2026-45659 and CVE-2026-56164, are still open in your estate. Their deadlines have already passed.
- ✅ Run forensic triage on any instance that was internet reachable before the fix, rather than assuming the patch is the end of the task.
- ✅ Where a product cannot be mitigated in time, use the discontinuation path the required action explicitly allows.
The catalog is machine readable, so use it that way
CISA publishes KEV as a JSON feed, which means dateAdded, dueDate, requiredAction and knownRansomwareCampaignUse can be checked against an asset inventory automatically instead of being read from a news article. It is also the starting point for recovering encrypted files if triage does find an intrusion.
Sources
Juan Ricardo Palacio
Co-Founder and CEO for the Americas, HelpRansomware
Juan Ricardo Palacio is an electronic engineer, entrepreneur, and specialist in telecommunications, cybersecurity, and digital forensics, with more than 25 years of professional experience. As Co-Founder of HelpRansomware, he works across cyber resilience, ransomware incident response, data recovery, cryptography, and reverse engineering, supporting companies and organizations through high-impact cyber incidents.
📰 Featured and quoted in Forbes Georgia, Business Insider Africa, LA Weekly, and Il Sole 24 Ore.
📅 Last updated: 17 July 2026



