CISA adds FortiSandbox and SharePoint flaws to KEV with a three day deadline

AI Overview

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on 16 July 2026: two OS command injection flaws in Fortinet FortiSandbox and one deserialization flaw in Microsoft SharePoint. All three carry a 19 July remediation deadline. For all three, the KEV field for known ransomware campaign use reads Unknown.

Juan Ricardo Palacio, Co-Founder of HelpRansomware

Juan Ricardo Palacio

Co-Founder and CEO for the Americas, HelpRansomware

Electronic engineer and Co-Founder of HelpRansomware, with 25+ years in cybersecurity, digital forensics and ransomware incident response.

Three days. That is the entire distance between a vulnerability appearing on CISA’s Known Exploited Vulnerabilities catalog on 16 July 2026 and the date by which federal agencies must have it fixed. In April, the same catalog gave fourteen.

CISA added three actively exploited vulnerabilities to the KEV catalog on 16 July 2026, all with a remediation deadline of 19 July. Two affect Fortinet FortiSandbox (CVE-2026-25089 and CVE-2026-39808, both OS command injection reachable without authentication). One affects Microsoft SharePoint (CVE-2026-58644, deserialization of untrusted data leading to remote code execution). The catalog now lists 1,647 entries.

Read the KEV metadata before you read the headlines

For CVE-2026-25089, CVE-2026-39808 and CVE-2026-58644 the KEV field knownRansomwareCampaignUse reads Unknown. That is the catalog stating it has no evidence tying these flaws to a ransomware campaign. Treat them as what the record supports: actively exploited remote code execution on exposed infrastructure. Nothing in the KEV entry justifies a ransomware label, and the absence of that label does not lower the urgency of the deadline.

What CISA published on 16 July 2026

The three entries added to the catalog, as recorded in the KEV JSON:

  • CVE-2026-25089, Fortinet FortiSandbox OS Command Injection Vulnerability. FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS contain an OS command injection flaw that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Vendor advisory FG-IR-26-141.
  • CVE-2026-39808, Fortinet FortiSandbox OS Command Injection Vulnerability. FortiSandbox contains an OS command injection flaw that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. Vendor advisory FG-IR-26-100.
  • CVE-2026-58644, Microsoft SharePoint Deserialization of Untrusted Data Vulnerability. SharePoint contains a deserialization of untrusted data flaw that allows an unauthorized attacker to execute code over a network.
  • All three were added on 16 July 2026 with a due date of 19 July 2026.
  • The required action for all three is to apply vendor mitigations in line with CISA Binding Operational Directive 26-04 and the Forensics Triage Requirements, or discontinue use of the product if mitigations are unavailable.

The 16 July KEV batch in numbers

3
CVEs added to the KEV catalog on 16 July 2026
3
days from KEV listing to the remediation deadline
1647
total entries in the KEV catalog as of 16 July 2026
Unknown
known ransomware campaign use recorded for all three

All figures are read directly from the CISA Known Exploited Vulnerabilities JSON catalog, version 2026.07.16. The catalog is the authoritative record for dateAdded, dueDate, requiredAction and knownRansomwareCampaignUse. No third party interpretation is included in the numbers above.

What the catalog actually requires

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.

CISA, KEV required action for CVE-2026-25089, CVE-2026-39808 and CVE-2026-58644

How the patch window closed

The interesting figure in this batch is not the CVSS score. It is the gap between dateAdded and dueDate, and how that gap has changed across 2026 as CISA moved from BOD 22-01 to BOD 26-04. For the wider pattern, see how a ransomware attack usually unfolds.

14 April 2026
CVE-2026-32201 (Microsoft SharePoint Server, improper input validation) is added to KEV with a due date of 28 April. The required action cites BOD 22-01. The window is fourteen days.
1 July 2026
CVE-2026-45659 (SharePoint Server, deserialization of untrusted data) is added with a due date of 4 July. The window is three days.
14 July 2026
CVE-2026-56164 (SharePoint, missing authentication for a critical function) is added with a due date of 17 July. Three days again.
16 July 2026
CVE-2026-25089 and CVE-2026-39808 (Fortinet FortiSandbox) are added with a due date of 19 July, under BOD 26-04 and the Forensics Triage Requirements.
16 July 2026
CVE-2026-58644 (Microsoft SharePoint) is added the same day with the same 19 July deadline, bringing the catalog to 1,647 entries.

Days between KEV listing and deadline

The remediation window narrowed from fourteen days to three

CISA KEV JSON catalog, version 2026.07.16

Bar chart comparing days between KEV listing and remediation deadline: 14 days for CVE-2026-32201 in April under BOD 22-01, and 3 days each for CVE-2026-45659, CVE-2026-56164, CVE-2026-25089 and CVE-2026-39808 in July.

📊 Read it this way: each bar is the dueDate minus the dateAdded recorded in the KEV entry itself. The April entry cites BOD 22-01, the July entries cite BOD 26-04. The window is a policy change, not an estimate.

Controls that match these specific entries

The controls below map to what the KEV entries actually describe, which is unauthenticated remote code execution against a security appliance and a collaboration server. They are not a generic hardening list.

Control Why it matters for this KEV batch Gap it closes
Inventory of internet facing appliances Both FortiSandbox entries describe an unauthenticated attacker reaching the product over crafted HTTP requests Appliances nobody owns because they are considered security tooling
Three day patch SLA for KEV entries The required action ties remediation to BOD 26-04 deadlines, which in this batch is 19 July Patch cycles measured in weeks against a catalog measured in days
Vendor advisory subscription The KEV notes point to FG-IR-26-141 and FG-IR-26-100 for the mitigation detail Waiting for press coverage instead of the PSIRT advisory
Forensic triage readiness The required action explicitly cites CISA Forensics Triage Requirements alongside patching Patching an exploited box and destroying the evidence of whether it was already used
Decommission path The required action allows discontinuing use of the product if mitigations are unavailable No plan for an appliance that cannot be patched in time

Where this goes wrong in practice

The failure modes below are not hypothetical risks. They follow directly from the structure of the KEV entries in this batch.

  • ⛔ Treating a security appliance as infrastructure that protects rather than infrastructure that is exposed. FortiSandbox is reachable over HTTP in both entries.
  • ⛔ Reading a KEV listing as a ransomware warning. The catalog records Unknown for ransomware campaign use on all three entries, and inventing that link is a reporting error, not a precaution.
  • ⛔ Planning remediation on a monthly cycle when the catalog issues three day deadlines.
  • ⛔ Patching first and triaging never, when the required action names forensic triage as part of the obligation.
  • ⛔ Assuming the deadline only binds federal agencies, and therefore ignoring that the deadline exists because exploitation is already confirmed.

Patching does not tell you whether you were already reached

A KEV entry means exploitation has been observed somewhere, before the deadline was set. Applying the vendor fix closes the door but says nothing about who walked through it first. That is precisely why the required action for these three entries pairs mitigation with the CISA Forensics Triage Requirements rather than listing patching alone.

What to do before 19 July

None of the following needs a new budget line. They follow the required action recorded in the KEV entries themselves, in the order that reduces exposure fastest. For the full checklist, see our guide on preventing a ransomware attack.

  • ✅ Confirm whether FortiSandbox, FortiSandbox Cloud or FortiSandbox PaaS is deployed anywhere in the estate, including instances owned by the security team rather than IT.
  • ✅ Apply the mitigations in Fortinet advisories FG-IR-26-141 and FG-IR-26-100, and the Microsoft update guide entry for CVE-2026-58644.
  • ✅ Check whether the SharePoint entries added on 1 and 14 July, CVE-2026-45659 and CVE-2026-56164, are still open in your estate. Their deadlines have already passed.
  • ✅ Run forensic triage on any instance that was internet reachable before the fix, rather than assuming the patch is the end of the task.
  • ✅ Where a product cannot be mitigated in time, use the discontinuation path the required action explicitly allows.

The catalog is machine readable, so use it that way

CISA publishes KEV as a JSON feed, which means dateAdded, dueDate, requiredAction and knownRansomwareCampaignUse can be checked against an asset inventory automatically instead of being read from a news article. It is also the starting point for recovering encrypted files if triage does find an intrusion.


Sources

Juan Ricardo Palacio, Co-Founder of HelpRansomware

Juan Ricardo Palacio

Co-Founder and CEO for the Americas, HelpRansomware

Juan Ricardo Palacio is an electronic engineer, entrepreneur, and specialist in telecommunications, cybersecurity, and digital forensics, with more than 25 years of professional experience. As Co-Founder of HelpRansomware, he works across cyber resilience, ransomware incident response, data recovery, cryptography, and reverse engineering, supporting companies and organizations through high-impact cyber incidents.

📰 Featured and quoted in Forbes Georgia, Business Insider Africa, LA Weekly, and Il Sole 24 Ore.

📅 Last updated: 17 July 2026

Leave a Comment

Your email address will not be published. Required fields are marked *