The U.S. Cybersecurity and Infrastructure Security Agency has ordered federal civilian agencies to patch two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform by Sunday, according to an advisory published Thursday.
The vulnerabilities, which have been added to CISA’s Known Exploited Vulnerabilities catalog, affect Fortinet’s FortiSandbox platform, a network security appliance used for advanced threat detection and analysis. CISA’s directive requires all Federal Civilian Executive Branch agencies to apply the available patches or implement authorized mitigations within the specified timeline.
While CISA’s Binding Operational Directive applies directly only to federal agencies, cybersecurity experts recommend that all organizations using FortiSandbox appliances prioritize patching, given that the flaws are already being exploited in active attacks. The agency did not disclose specific details about the nature of the attacks or which threat actors may be exploiting the vulnerabilities.
Fortinet has released security updates for the affected products. Organizations that cannot immediately apply patches should review Fortinet’s advisory for recommended workarounds and mitigation measures, which may include restricting access to the management interface and disabling vulnerable features.
The advisory is part of CISA’s ongoing effort to reduce the window of exposure for known exploited vulnerabilities. The agency maintains a public catalog of vulnerabilities known to be exploited in the wild, which it updates regularly as new threats are identified.
Organizations using Fortinet products are advised to maintain awareness of security advisories from the vendor and apply patches promptly, particularly for internet-facing appliances that represent attractive targets for remote attackers.
This article was adapted from Bleeping Computer. Read the original here.
