- Sources: CVE-2026-58644 (NVD), CISA KEV catalog, FortiSandbox FG-IR-26-141, FortiSandbox FG-IR-26-100, HN discussion
- Summary: CISA added three vulnerabilities to the Known Exploited Vulnerabilities catalog on 2026-07-16 (catalog version 2026.07.16, count 1647). CVE-2026-58644 is a deserialization-of-untrusted-data flaw in Microsoft SharePoint (CWE-502, CVSS 9.8) that lets an unauthenticated attacker execute code over the network. Fixed builds are SharePoint 2016 16.0.5556.1005, SharePoint 2019 16.0.10417.20153, and Subscription Edition 16.0.19725.20384. CVE-2026-25089 and CVE-2026-39808 are OS command injection flaws in Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that allow unauthenticated command execution via crafted HTTP requests, fixed in FortiSandbox 4.4.9 and 5.0.6 (Cloud and PaaS on 5.0.6). All three carry a federal remediation deadline of 2026-07-19.
- Why it matters: All three are unauthenticated remote-code paths on internet-facing enterprise infrastructure, and the three-day federal deadline signals confirmed active exploitation.
- Follow-up: Watch for ransomware follow-on, exposure scans of unpatched SharePoint and FortiSandbox appliances, and whether the SharePoint deserialization flaw joins the earlier July SharePoint KEV entries in a single exploitation cluster.
send feedback on this story