[Verse 1] SharePoint's running quiet on the corporate floor CVE-2026-58644 is cracking at the door Microsoft's serialization trusts the data that arrives An attacker sends a payload, watches foreign code revive Deserialization — that's the flaw in the machine It unpacks untrusted objects, executes what's in between No credentials, just a network, and your server's been received Unauthorized execution — harder than you'd have believed [Chorus] Critical CVEs, July twenty-twenty-six Three exploits in the open, time to get your patches fixed SharePoint and FortiSandbox, vectors wide and raw Arbitrary code is running — read the advisory, read the law These aren't hypothetical, the threat is reified — Made structurally real, no longer dormant, now it's live outside Patch your systems, block those vectors, audit what you've deployed Critical CVEs — don't leave your perimeter destroyed [Verse 2] Fortinet's FortiSandbox, built to cage malicious code CVE-2026-25089 found a hidden road OS command injection — slipping directives through the wire Unauthenticated caller sending packets in the mire Specially crafted packets, and the sandbox runs the deed No login, no identity, just weaponized input feed The system meant to analyze is now the one betrayed FortiSandbox Cloud and PaaS — the whole platform's been frayed [Chorus] Critical CVEs, July twenty-twenty-six Three exploits in the open, time to get your patches fixed SharePoint and FortiSandbox, vectors wide and raw Arbitrary code is running — read the advisory, read the law These aren't hypothetical, the threat is reified — Made structurally real, no longer dormant, now it's live outside Patch your systems, block those vectors, audit what you've deployed Critical CVEs — don't leave your perimeter destroyed [Bridge] 39808 — second Fortinet strike Crafted HTTP requests executing what attackers like Command injection through the request layer, no auth required Unauthenticated code execution, consequence acquired Two separate CVEs, same product, different seams Fortinet's architecture wider open than it seems Stack your remediations, double-check your firmware strain One patch covers something the other won't contain [Verse 3] Three vulnerabilities, one Monday morning brief Deserialization, injection — no relief The perimeter you trust is only strong as what you run Unpatched code is exposure — and exposure means you're done Review your SharePoint versioning, check FortiSandbox builds Apply Fortinet's bulletins before the attacker instills These aren't edge-case laboratory flaws collecting dust Network-reachable, unauthenticated — react or combust [Outro] CVE-2026-58644 — serialize with care 25089 and 39808 — injected in the air FortiSandbox, SharePoint — July twenty-twenty-six Critical, reified, and active — go and get your patches fixed
← Canada Gazette — July 20, 2026 | Critical CVEs (2 of 3) — July 20, 2026 →