FortiSandbox, SharePoint & Oracle Flaws Under Active Attack : CISA Orders Immediate Action

Let me ask you something: when you leave your house for the day, do you just lock the front door?

Most likely, you check the back door too. Maybe you make sure the windows are latched. It makes sense. Why leave a single point of entry open for someone to wander in?

Now, imagine you’ve locked everything up tight, but your security system itself has a "backdoor" you didn't even know existed. That’s exactly what’s happening in the digital world right now.

You're scanning your inbox, checking on your team, and managing your operations. Meanwhile, hackers are actively using newfound "windows" in some of the most common business software to slip into networks unnoticed.

The Cybersecurity and Infrastructure Security Agency (CISA) just issued a series of urgent warnings between July 17 and July 18, 2026. They aren't just suggestions. For federal agencies, these are orders with deadlines as short as 48 hours.

If you’re a business owner, you might think, "I'm not a federal agency. Does this really apply to me?"

The truth is, hackers don't check your tax ID before they strike. They look for the path of least resistance. And right now, these specific flaws in Fortinet, SharePoint, and Oracle are the widest paths available.

Here’s exactly what is happening and, more importantly, what you need to do about it.

The "Big Three" Threats Under Fire

When CISA adds a vulnerability to their "Known Exploited Vulnerabilities" (KEV) catalog, it means the house is already on fire. These aren't theoretical risks; these are tools currently being used by cybercriminals to steal data and deploy ransomware.

1. Fortinet FortiSandbox: The Security Guard is Compromised

Fortinet is a titan in the security world. Their FortiSandbox is designed to catch threats before they reach your network. But right now, two critical flaws (CVE-2026-39808 and CVE-2026-25089) have turned the guard into a target.

These are "OS Command Injection" vulnerabilities. In plain English? An attacker can send a specific command to your system and it will simply execute it, no questions asked.

And here’s the scary part: they don't even need a password.

Because a public exploit is already available, anyone with basic technical skills can attempt this. CISA has set a federal patch deadline of July 19. If the government is moving that fast, you should too.

2. Microsoft SharePoint Server: The Zero-Day in Your Files

You likely use SharePoint to store documents and collaborate. It’s the heart of many business operations. Unfortunately, a critical "Zero-Day" (CVE-2026-58644) was discovered being exploited before a fix was even widely known.

This is a "deserialization" flaw. Think of it like a puzzle being sent through the mail. When your server tries to put the pieces together, the puzzle "explodes" and gives the attacker full control over the machine (Remote Code Execution, or RCE).

Like the Fortinet flaw, the federal deadline to fix this is July 19. If you run an on-premises SharePoint server, you are in the crosshairs.

3. Oracle E-Business Suite: The Keys to the Kingdom

If your business uses Oracle for finance or supply chain management, pay close attention. CVE-2026-46817 involves improper privilege management.

Imagine giving a temporary contractor a key to the supply closet, only to find out that same key opens the safe and the CEO's office. An unauthenticated attacker can exploit this via the web to take over your financial systems.

The deadline for this was July 18. If you haven't checked your Oracle systems this weekend, you are already behind the curve.

IT specialist monitoring security metrics in a professional setting

The "Silent" Risks: KNX and Industrial Controls

While the big names like Microsoft and Oracle grab the headlines, there are other vulnerabilities that are just as dangerous for specific industries.

The Smart Building Problem (KNX Association)

Do you have a "smart" office? Systems that control your lighting, HVAC, or security cameras often use the KNX protocol.

CISA flagged CVE-2023-4346, which affects the account lockout mechanism. This might sound minor, but it allows attackers to brute-force their way into your building's automation systems.

The deadline for this is July 29. It's a reminder that cybersecurity isn't just about your laptop; it's about the physical walls and wires around you.

Industrial Control Systems (ICS) Under Attack

On July 16, nine new advisories were released covering everything from Rockwell Automation and Siemens to systems used by NASA. These affect the hardware that runs manufacturing floors, water systems, and power grids.

If your business involves any kind of automated machinery or industrial hardware, your "IT" world and your "Physical" world have collided. A breach here doesn't just lose data: it stops production.

Smart building automation security concept on a tablet

Why This Matters to Your Small Business

It’s easy to feel overwhelmed by all the technical jargon. "Deserialization RCE" and "OS Command Injection" sound like something out of a sci-fi movie.

But here’s the reality for a small business owner:

1. Operational Paralysis
If your SharePoint server is hit with RCE, your files disappear. Your team can't work. Your customers can't get answers. The downtime alone can cost thousands of dollars per hour.

2. The Ransomware Pipeline
Hackers don't usually just "visit." They use these flaws to plant a seed. They might sit in your system for weeks, learning your habits, before locking your entire business behind a ransomware screen. These CISA warnings are the "early detection" that can prevent a total catastrophe.

3. Reputation Damage
If your Oracle system is compromised and your financial data: or your customers' data: is leaked, how do you explain that to your clients? Trust is hard to build and incredibly easy to break.

4. The "Internet-Facing" Target
The biggest takeaway from this week's updates is that internet-facing systems are the primary target. If your server is connected to the web, hackers are scanning it right now. They don't need to know who you are; they just need to see that you haven't patched CVE-2026-58644 yet.

Platinum Insight: Your Action Plan

At Platinum Web Services, we believe you shouldn't have to stay up at night worrying about CISA advisories. That’s our job. But if you are managing your own IT, here is what you need to do immediately:

  • Audit Your Assets: Do you use FortiSandbox? Do you have an on-premises SharePoint server? Are you running Oracle E-Business Suite? If you don't know, find out today.
  • Prioritize the "Criticals": Not all updates are equal. Focus on the Fortinet and SharePoint patches first. These are being exploited now.
  • Close the Windows: Review any system that is "internet-facing." If a management interface doesn't need to be accessible from the public web, lock it down behind a VPN.
  • Check Your Backups: Before you run any major update, ensure your data is backed up and: more importantly: that the backup actually works.
  • Turn to Proactive Support: If this list makes your head spin, it might be time to move away from "break-fix" IT.

The truth is, most people don't miss these updates on purpose. They just have a business to run.

That’s where we come in. We offer personalized IT solutions that prioritize your security so you can focus on growth. We don't just wait for things to break; our proactive strategy uses predictive analytics and meticulous system management to ensure these vulnerabilities are closed before a hacker even finds them.

Cyber security shield on a laptop in a modern office

Don't Wait for the Breach

Cybersecurity is a race. Right now, the hackers have the map, but you have the locks.

The deadlines set by CISA for these vulnerabilities are incredibly tight for a reason: the risk is high, and the exploit is easy. Whether it's your cybersecurity solutions or your cloud services, every part of your infrastructure needs a watchful eye.

If you’re feeling exposed or just want a second pair of eyes on your network, we’re here to help. We help businesses like yours with these exact challenges every day, providing enterprise-level safeguards against ransomware and phishing.

Get in touch with us today for a consultation. Let’s make sure your "digital windows" are locked tight before the next storm rolls in.

We’re Platinum Web Services, and we’re here to give you the peace of mind you deserve.

Two professionals collaborating on IT solutions at a conference table

0 Comments