Bottom line: CISA has issued a binding patch mandate for two in-the-wild exploited Fortinet vulnerabilities, requiring immediate remediation by federal agencies.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has instructed federal agencies to patch two actively exploited vulnerabilities in Fortinet’s FortiSandbox platform with highest priority. The vulnerabilities are already being exploited in targeted attacks.
CISA ordered on Thursday that U.S. federal agencies must remediate two actively exploited vulnerabilities in the Fortinet FortiSandbox Threat Detection platform as a priority matter. The vulnerabilities are currently being exploited in campaigns outside of test environments, significantly increasing the risk to critical infrastructure.
For CISO teams, this means an immediate mandate for action: systems running FortiSandbox must be inventoried and reviewed. While this CISA directive formally applies only to federal agencies, it de facto sets a standard for the entire business sector, particularly in regulated industries. Any delay in patching will be critically scrutinized in audits and compliance assessments.
Fortinet users should immediately review available security updates, test patch compatibility with their infrastructure, and create a staged deployment plan. If immediate patching is not feasible, compensating measures such as network segmentation or enhanced monitoring should be activated. The time constraint set by CISA underscores the criticality: further delays significantly increase the risk of exploitation.
Source: www.bleepingcomputer.com · Published July 17, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.