Back to all lessons
Awareness Lessons
3 months ago

CISA Flags Three Actively Exploited Vulnerabilities Demanding Urgent Remediation

Three critical vulnerabilities — two OS command injection flaws in Fortinet FortiSandbox and a deserialization vulnerability in Microsoft SharePoint — are being actively exploited in the wild, prompting CISA to add them to its Known Exploited Vulnerabilities Catalog. Command injection and deserialization flaws are particularly dangerous because they can allow attackers to execute arbitrary code remotely, potentially leading to full system compromise. Federal agencies are legally required under BOD 26-04 to remediate these vulnerabilities on internet-facing assets within mandated timeframes, but the risk extends equally to private sector organizations. Delayed patching of publicly exposed systems dramatically increases the attack surface and the likelihood of a successful breach. The KEV Catalog serves as a critical, intelligence-driven prioritization tool that all organizations should integrate into their vulnerability management programs.

Tactical Insight

Immediate Actions

  • Apply vendor-released patches for CVE-2026-25089, CVE-2026-39808 (Fortinet FortiSandbox), and CVE-2026-58644 (Microsoft SharePoint) as soon as possible.
  • Audit all internet-facing assets to identify any exposed instances of affected Fortinet and Microsoft products.
  • If patches cannot be applied immediately, restrict public access to affected systems or place them behind a VPN as a temporary mitigation.

Long-Term Improvements

  • Subscribe to and regularly monitor the CISA KEV Catalog to maintain awareness of actively exploited vulnerabilities requiring prioritized remediation.
  • Implement a risk-based vulnerability management program that automatically escalates KEV-listed CVEs to emergency patch priority.
  • Maintain a continuously updated, authoritative inventory of all internet-facing assets to enable rapid impact assessment when new vulnerabilities are disclosed.

Detection Measures

  • Deploy web application firewalls and intrusion detection signatures tuned to detect exploitation attempts targeting command injection and deserialization attack patterns.
  • Enable centralized logging and alerting for anomalous activity on FortiSandbox and SharePoint systems, including unexpected process execution or unusual authentication events.
  • Conduct threat hunting exercises on potentially affected systems to identify indicators of compromise that may predate the patch.