CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability
- CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability
- CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
This product is provided subject to this Notification and this Privacy & Use policy.
Facts Only
* CVE-2026-25089 is a Fortinet FortiSandbox OS Command Injection Vulnerability.
* CVE-2026-39808 is a Fortinet FortiSandbox OS Command Injection Vulnerability.
* CVE-2026-58644 is a Microsoft SharePoint Deserialization of Untrusted Data Vulnerability.
* Binding Operational Directive (BOD) 26-04 establishes vulnerability management requirements for FCEB agencies.
* BOD 26-04 reinforces the importance of the KEV Catalog and mandates prioritizing rapid remediation for high-risk vulnerabilities on publicly exposed assets that grant post-exploitation control.
* CISA encourages all organizations to adopt risk-based vulnerability management.
* Exploited vulnerabilities can be submitted for potential addition to the KEV Catalog via CISA’s KEV Nomination Form if they have a CVE ID, exploitation evidence, and mitigation guidance.
Executive Summary
Full Take
The mechanism described establishes a tiered system of mandatory prioritization rooted in observed threat activity. The shift from general vulnerability management to prioritizing KEV items on publicly exposed assets suggests a response calibrated by immediate risk exposure rather than theoretical CVSS scores alone. This creates a dynamic tension between the mandate for rapid remediation under BOD 26-04 and the operational reality of assessing system state, specifically whether compromise has already occurred prior to patching. The encouragement for external reporting via nomination forms introduces an element where private actors become contributors to the public risk assessment structure, complicating the chain of custody and verification required for catalog updates. Furthermore, the explicit focus on 'total control post-exploitation' frames remediation not just as a technical fix but as a critical sovereignty defense against deep system compromise. The implication is that organizational resilience must account for both known exploits and potential prior compromise indicators to effectively manage federal risk.
Bridge Questions: How can organizations develop standardized, auditable processes for assessing "prior compromise" status? What mechanisms should exist to ensure the quality and veracity of vulnerability nominations submitted to CISA? How does the reliance on a centralized catalog affect the distributed decision-making authority within different organizational sectors?
Sentinel — Human
The text functions as a direct dissemination of official security updates and policy context, exhibiting the structure and specific detail of human-generated governmental communication rather than typical synthesized news reporting.
