Robotics & Physical AIJul 16, 2026
Patch now: CISA flags actively exploited Microsoft SharePoint and Fortinet FortiSandbox flaws
CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on July 16: a Microsoft SharePoint deserialization-of-untrusted-data flaw (CVE-2026-58644) and two OS command-injection flaws in Fortinet FortiSandbox (CVE-2026-25089, CVE-2026-39808). KEV listing puts US federal agencies on a remediation deadline — everyone else should treat it as a patch-first list.
What it means If you run on-prem SharePoint or FortiSandbox, attackers are already exploiting these — patch before the weekend.
Where it came from CISA