cisa-kev
CISA KEVExtracts: CVE id, vendor, due date · metadata or bounded excerpt
Retention: D1 event history with canonical source link and deduplication metadata.
Access basis: Public endpoint; no project credential required.
Last ingested: 2026-08-26 · run status: success with data
- 2026-07-16CISA KEV: Fortinet / FortiSandbox / Fortinet FortiSandbox OS Command Injection Vulnerability
CVE: CVE-2026-39808 Vendor/project: Fortinet Product: FortiSandbox Known ransomware campaign use: Unknown Due date: 2026-07-19 CWE: CWE-78 Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized cod
- 2026-07-16CISA KEV: Fortinet / FortiSandbox / Fortinet FortiSandbox OS Command Injection Vulnerability
CVE: CVE-2026-25089 Vendor/project: Fortinet Product: FortiSandbox Known ransomware campaign use: Unknown Due date: 2026-07-19 CWE: CWE-78 Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated
CVE: CVE-2026-58644 Vendor/project: Microsoft Product: SharePoint Known ransomware campaign use: Unknown Due date: 2026-07-19 CWE: CWE-502 Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a n