The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch two critical vulnerabilities in Fortinet's FortiSandbox products.

The flaws, identified as CVE-2026-39808 and CVE-2026-25089, carry a high severity rating of 9.1 CVSS.

Hackers are currently exploiting these vulnerabilities in the wild.

CISA added the flaws to its Known Exploited Vulnerabilities catalog on July 16.

Federal agencies must apply the necessary patches by the July 19 deadline.

Successful attacks allow unauthenticated users to execute unauthorized code or commands remotely.

Fortinet previously released patches for these specific issues in April and June.