CISA adds three Fortinet and SharePoint CVEs to KEV
BOD 26-04 turns these listings into federal patch priority, while the alert itself does not state a standalone remediation deadline.
TL;DR
CISA added CVE-2026-25089 and CVE-2026-39808, both Fortinet FortiSandbox OS command injection flaws, and CVE-2026-58644, a Microsoft SharePoint deserialization flaw, to the Known Exploited Vulnerabilities (KEV) Catalog. Binding Operational Directive (BOD) 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of KEV-listed CVEs on publicly exposed assets that grant total control after exploitation. Contractors and managed service providers inherit the urgency when they operate those federal environments.
This is a routine Known Exploited Vulnerabilities (KEV) update, which means the three CVEs are less interesting than the rule the alert invokes. CISA listed two Fortinet FortiSandbox OS command injection vulnerabilities, CVE-2026-25089 and CVE-2026-39808, and one Microsoft SharePoint deserialization vulnerability, CVE-2026-58644, based on evidence of active exploitation. Binding Operational Directive (BOD) 26-04 requires Federal Civilian Executive Branch (FCEB) agencies to prioritize rapid remediation of high-risk KEV-listed CVEs on publicly exposed assets that would give an attacker total control after exploitation. It also sets expectations for checking whether a system was compromised before the patch landed. The alert says BOD 26-04 applies only to FCEB agencies, so primes, contractors and managed service providers feel this through the federal environments they run. If they administer FortiSandbox or SharePoint for government customers, their patch sequencing needs to match the agency’s BOD 26-04 obligations.
Published ·Deep Fathom