CISA's list that day
16 July 2026
On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Fortinet FortiSandbox and Microsoft SharePoint. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-25089OS Command Injection | Fortinet FortiSandbox | Patch nowForensic triage required by CISA | 0.76 | ||
| CVE-2026-39808OS Command Injection | Fortinet FortiSandbox | Patch nowForensic triage required by CISA | 0.47 | ||
| CVE-2026-58644Deserialization of Untrusted Data | Microsoft SharePoint | Patch nowForensic triage required by CISA | 0.16 |