The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two high-severity vulnerabilities—one affecting Fortinet's FortiSandbox and the other in on-premises Microsoft SharePoint—to its Known Exploited Vulnerabilities (KEV) catalog, signaling confirmed active exploitation and urgent remediation needs for organizations worldwide.
As reported by Security Affairs, the inclusion of these flaws in the KEV catalog serves as a critical alert to the cybersecurity community. While CISA's remediation directives are legally binding only for Federal Civilian Executive Branch (FCEB) agencies, the catalog functions as a global benchmark, urging all organizations to treat listed vulnerabilities as immediate priorities.
The more severe of the two affects Fortinet FortiSandbox, a tool designed to analyze and contain potential threats. The vulnerability allows unauthenticated attackers to compromise the FortiSandbox security appliance itself—a breach that could undermine the core defensive architecture of affected organizations. Organizations should immediately inventory all FortiSandbox deployments and prioritize applying the vendor patch.
The second vulnerability affects Microsoft SharePoint Server 2019 and Subscription Edition. Microsoft addressed the remote code execution flaw as part of its July 2026 Patch Tuesday release. CISA's swift addition of this vulnerability to the KEV catalog, shortly after the Patch became available, indicates assessments of severe, real-world exploitation that has outpaced standard advisory timelines. Ensuring complete deployment of the July 2026 Patches across all SharePoint servers is essential.
Security experts recommend that organizations treat both flaws as critical priorities. The inclusion of these vulnerabilities in the KEV catalog underscores an enduring trend: attackers are aggressively targeting trusted security tools and widely deployed enterprise platforms. Prompt, validated patching remains the most effective defense against such confirmed threats.
美國網絡安全和基礎設施安全局(CISA)已將兩個高嚴重性漏洞——一個影響 Fortinet 的 FortiSandbox,另一個存在於本地部署的 Microsoft SharePoint 中——加入其已知被利用漏洞(KEV)目錄,表明已確認的積極利用行為,以及全球各組織緊急的修補需求。
據《Security Affairs》報導,這些漏洞被納入 KEV 目錄,對網絡安全界構成關鍵警報。雖然 CISA 的修補指令僅對聯邦民事行政部門(FCEB)機構具有法律約束力,但該目錄作為全球基準,敦促所有組織將列於清單的漏洞視為即時處理的優先事項。
其中較嚴重的一個影響 Fortinet FortiSandbox——一款旨在分析和遏制潛在威脅的工具。此漏洞允許未經驗證的攻擊者入侵 FortiSandbox 安全設備本身——此入侵行為可能削弱受影響組織的核心防禦架構。各組織應立即清點所有 FortiSandbox 部署,並優先套用供應商提供的 Patch。
第二個漏洞影響 Microsoft SharePoint Server 2019 及訂閱版。微軟在其 2026 年 7 月 Patch Tuesday 發佈中處理了此遠端程式碼執行缺陷。CISA 在 Patch 發佈後迅速將此漏洞加入 KEV 目錄,表明其評估認為已發生嚴重的現實世界利用行為,其速度已超出標準安全公告的時間表。確保所有 SharePoint 伺服器完全部署 2026 年 7 月的 Patch 至關重要。
安全專家建議各組織將這兩個漏洞視為關鍵優先事項。這些漏洞被納入 KEV 目錄,凸顯了一個持續趨勢:攻擊者正積極針對受信任的安全工具和廣泛部署的企業平台。及時且經驗證的修補,仍是對抗此類已確認威脅最有效的防禦手段。
