FortiSandbox and SharePoint Under Active Attack , CISA Sets Emergency Patch Deadline

Let me ask you something: When you leave your office for the day, do you double-check the front door?

Of course you do. It’s second nature. You wouldn't leave the keys in the lock or the windows wide open, especially if you knew there was a string of break-ins in your neighborhood.

Well, right now, the digital windows of thousands of businesses are wide open, and the "neighborhood" is crawling with activity.

This weekend, the Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency alert that every small business owner needs to hear. They’ve added several critical vulnerabilities to their "Must-Patch" list (the KEV catalog).

And here’s where it gets scary: the deadline to fix these issues is today, July 19.

If your business uses Fortinet FortiSandbox or Microsoft SharePoint, your digital "front door" might be unlocked. And hackers aren't just knocking: they’re already turning the handle.

The Problem: Why This Isn't "Just Another Update"

At Platinum Web Services, we see a lot of security alerts. Most are important, but some are "drop everything and fix this now" important.

This is the latter.

CISA has confirmed that attackers are actively exploiting three major flaws in FortiSandbox and SharePoint. These are what we call unauthenticated Remote Code Execution (RCE) vulnerabilities.

Think of it like this: an RCE is the digital equivalent of a master key. It allows an attacker to walk into your systems, sit down at the desk, and start running programs, stealing files, or locking you out entirely.

And the "unauthenticated" part? That means they don't even need a username or a password to get in.

They don't need to trick your employees with a phishing email (pronounced "fishing"). They don't need to guess a weak password. They just need to find your server on the internet and send it a specifically crafted message.

Just like that, they’re in.

The FortiSandbox Crisis (CVE-2026-25089 & CVE-2026-39808)

If you use FortiSandbox to catch malware before it hits your network, you’re using a great tool. But right now, that tool has a massive hole in it.

Two specific flaws (CVE-2026-25089 and CVE-2026-39808) are being used by hackers to inject commands directly into the operating system of the device. With a CVSS score of 9.8 out of 10, this is as close to a "perfect 10" for danger as it gets.

Research shows that these attacks are happening right now. Hackers are using the "start VNC" function of the web interface to take control. If your FortiSandbox is facing the public internet, it is a target.

The SharePoint Threat Chain (CVE-2026-58644 and others)

SharePoint is a staple for small businesses. It’s where you store your documents, collaborate with your team, and keep your business running.

But a new flaw (CVE-2026-58644) involves "deserialization of untrusted data."

That sounds like a mouthful of tech-speak, right? Here’s the plain English version: when SharePoint receives data, it has to "unpack" it to understand what to do. The flaw allows an attacker to send "poisoned" data that, when unpacked, tells SharePoint to run the attacker's code.

Earlier this week, CISA also flagged three other SharePoint vulnerabilities (CVE-2026-56164, CVE-2026-45659, and CVE-2026-32201). When hackers string these together, they can bypass your security entirely, steal your "machine keys" (the master keys for your web server), and set up a permanent home in your network.

A digital shield on a laptop representing cyber security and proactive IT support

Beyond the Big Two: Other Risks on the Radar

While Fortinet and Microsoft are the headlines, CISA didn't stop there. They’ve added other serious threats to the list that could affect your business infrastructure:

  • Oracle E-Business Suite (CVE-2026-46817): A critical flaw in a system many businesses use for accounting and HR.
  • KNX Association Protocol (CVE-2023-4346): This affects building automation. Imagine a hacker being able to control the lights, locks, or thermostats in your building.
  • Industrial Control Systems (ICS): CISA released nine advisories on July 16 alone. These cover everything from Rockwell Automation hardware to Siemens systems.

You might think, "I'm a small business, I don't run a factory." But these systems are the backbone of modern buildings and utilities. When they are at risk, the entire business ecosystem feels the pressure.

The Business Impact: What’s Really at Stake?

We know you're busy. You're running a company, managing a team, and trying to grow. Patching servers on a Sunday probably isn't on your "fun" list.

But here’s the truth: if an attacker uses these flaws to get into your network, the cost is much higher than a few hours of downtime.

  1. Data Theft: Your client lists, financial records, and intellectual property could be gone in minutes.
  2. Ransomware: Once an attacker has RCE (Remote Code Execution) access, their next step is almost always to encrypt your files and demand a massive payout.
  3. Reputation Damage: If you have to tell your customers their data was stolen because of a known vulnerability you didn't patch, that trust is hard to win back.

CISA’s deadline for federal agencies is today for a reason. They recognize that the "window of opportunity" for hackers is wide open right now.

Platinum Insight: Your Action Plan

At Platinum Web Services, we believe in a proactive strategy. We don’t want you to worry about IT; we want you to focus on your business while we handle the heavy lifting.

If you are managing your own IT, here is exactly what you need to do right now:

For SharePoint Users:

  • Apply the July Updates: Install Microsoft’s July Patch Tuesday updates immediately.
  • Enable AMSI Integration: This is an extra layer of protection that helps "see" through the poisoned data attackers are sending.
  • Rotate Your Machine Keys: If you think you might have been targeted, changing these keys is like changing the locks on your house after a break-in.
  • Hunt for Trouble: Look through your logs for anything out of the ordinary.

For FortiSandbox Users:

  • Patch Immediately: Update to the latest versions (5.0.6, 4.4.9, or higher) provided by Fortinet.
  • Close the Door: If you can’t patch today, take the device off the public internet. Restrict access to only known, trusted IP addresses.
  • Audit Your Logs: Check for abnormal HTTP requests, specifically anything involving the web UI or VNC functions.

The SMB Golden Rule:

Prioritize the "Known Exploited Vulnerabilities" (KEV) list. Most businesses have hundreds of patches waiting. Don't treat them all the same. Focus on the ones CISA says are already being used in the wild.

Two professionals collaborating at a conference table reviewing IT solutions

How Platinum Web Services Can Help

The reality is that keeping up with daily CISA updates is a full-time job. You shouldn't have to spend your weekends reading technical advisories and worrying about "deserialization."

We offer Cyber Security Solutions and Proactive Strategy designed specifically for small businesses.

Our team provides:

  • 24/7 Monitoring: We watch your network while you sleep.
  • Automated Patch Management: We ensure critical updates are applied the moment they are available, prioritized by risk.
  • Personalized IT Support: We don't believe in one-size-fits-all. We tailor our security to your specific business needs.

Whether you need Laptop/Desktop Repairs or a full Network Design, we prioritize your security and peace of mind.

Final Thoughts

The digital landscape is changing fast. Threats that used to only target giant corporations are now hitting small businesses every single day.

But you aren't alone.

By taking action today: or by partnering with a team that takes action for you: you can turn your business from a target into a fortress.

Don't leave the digital windows open. Check the locks, apply the patches, and let's get back to growing your business.

If you’re feeling overwhelmed by these alerts or aren't sure if your systems are safe, we're here to help. At Platinum Web Services, we help businesses like yours stay secure every day.

Contact us today for a consultation and let's make sure your "front door" is locked tight.

A clean, modern workspace illustrating reliable technology consulting

0 Comments