Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
CVEVulnerability

Three FortiSandbox CVEs Under Active Exploit: Unauthenticated RCE

By ogwatermelon
June 17, 2026 4 Min Read
0
June 16, 2026

Threat actors are actively exploiting three critical vulnerabilities in Fortinet’s FortiSandbox threat detection platform. The flaws, tracked as CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, allow unauthenticated remote attackers to bypass authentication and execute arbitrary commands with low complexity and no user interaction.

What Happened: FortiSandbox Critical Flaws Now Under Active Exploit

Fortinet disclosed CVE-2026-39813 and CVE-2026-39808 on April 14, 2026, and CVE-2026-25089 on June 9, 2026. All three vulnerabilities carry a CVSS score of 9.1 and affect the FortiSandbox web user interface. An unauthenticated attacker can send crafted HTTP requests to exploit path traversal or OS command injection weaknesses.

Consequently, the attacker can escalate privileges and execute unauthorized code on the underlying operating system. Threat intelligence firm Defused Cyber confirmed active exploitation of all three CVEs within the past 24 hours. Moreover, Defused noted that the exploit for CVE-2026-25089 shows signs of being developed with artificial intelligence and is currently faulty. No working public exploit has been disclosed for that vulnerability yet.

Fortinet appliances have become a frequent target for ransomware gangs and nation-state actors. CISA currently tracks 26 Fortinet vulnerabilities in its Known Exploited Vulnerabilities catalog. Thirteen of those have been abused by ransomware operations.

Technical Details of the FortiSandbox Vulnerabilities

CVE-2026-39813 is a path traversal vulnerability in the FortiSandbox JRPC API. An unauthenticated attacker can bypass authentication by sending specially crafted HTTP requests. Therefore, any exposed FortiSandbox instance on versions 4.4.0 through 4.4.8 or 5.0.0 through 5.0.5 is at risk.

CVE-2026-39808 is an OS command injection flaw. An unauthenticated attacker can execute unauthorized commands via crafted HTTP requests. Similarly, CVE-2026-25089 is another OS command injection affecting the FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS web UI. Both command injection flaws require no credentials and no user interaction.

  • CVE-2026-39813 (CVSS 9.1): Path traversal in JRPC API; unauthenticated auth bypass
  • CVE-2026-39808 (CVSS 9.1): OS command injection; unauthenticated remote code execution
  • CVE-2026-25089 (CVSS 9.1): OS command injection in WEB UI; affects FortiSandbox, Cloud, and PaaS
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Attack Vector: Network

Business and Operational Impact

FortiSandbox is a dedicated threat detection appliance used by enterprises and government agencies to analyze suspicious files and detonate malware in isolated environments. If an attacker compromises the sandbox itself, they can pivot into the broader network, exfiltrate analyzed files, or disable the organization’s malware analysis capability.

In addition, the FortiSandbox Cloud and PaaS variants are affected. This expands the blast radius to organizations that rely on cloud-hosted or managed sandbox services rather than on-premises appliances. A compromised sandbox could also leak sensitive files uploaded for analysis, including proprietary intellectual property and customer data.

  • Security Control Compromise: The organization’s primary malware analysis platform becomes an attack vector
  • Data Exposure: Submitted files for analysis may be exfiltrated
  • Lateral Movement: Sandbox network access can enable pivoting to production systems
  • Compliance Risk: Loss of malware detection capability may violate security frameworks
  • Operational Downtime: Patching may require sandbox downtime during critical analysis periods

Mitigation and Recommendations

Fortinet released fixed versions on April 14 and June 9, 2026. Organizations must upgrade affected deployments immediately. Because all three vulnerabilities are unauthenticated and network-exploitable, any internet-facing or internally exposed FortiSandbox instance is a high-priority patching target.

Immediate Actions for Defenders

  1. Upgrade FortiSandbox to version 4.4.9 or above, or 5.0.6 or above.
  2. Upgrade FortiSandbox Cloud and PaaS instances to version 5.0.6 or above.
  3. Audit all FortiSandbox deployments for exposure to untrusted networks.
  4. Review web UI access logs for anomalous HTTP requests prior to patching.
  5. Inspect downstream systems for signs of lateral movement if exploitation is suspected.

Additional Guidance

If immediate patching is not feasible, restrict network access to the FortiSandbox web UI to trusted administrative IP ranges. Furthermore, monitor FortiSandbox logs for unexpected file uploads, command execution, or authentication events. Organizations should also review CISA’s Known Exploited Vulnerabilities catalog for related Fortinet entries and apply binding operational directives where applicable.

Bottom line: Three critical FortiSandbox vulnerabilities are under active exploit with no authentication required. Patch to 4.4.9+ or 5.0.6+ immediately, restrict network exposure, and hunt for indicators of compromise before attackers establish persistence.

Incident Summary

CVE ID / Incident: CVE-2026-39813, CVE-2026-39808, CVE-2026-25089 — Fortinet PSIRT FG-IR-26-112, FG-IR-26-100, FG-IR-26-141
Affected Systems: FortiSandbox 4.4.0–4.4.8, 5.0.0–5.0.5; FortiSandbox Cloud 5.0.4–5.0.5; FortiSandbox PaaS 5.0.4–5.0.5
Disclosure Date: April 14, 2026 (CVE-2026-39813, CVE-2026-39808); June 9, 2026 (CVE-2026-25089)
Patch Status: Fixed releases available: 4.4.9+, 5.0.6+
Active Exploitation: Confirmed by Defused Cyber as of June 15–16, 2026
Ransomware Context: Unknown at time of publication; 13 Fortinet KEV entries linked to ransomware

References

  1. Fortinet, “Path Traversal vulnerability in FortiSandbox JRPC API,” FortiGuard PSIRT FG-IR-26-112, April 14, 2026, https://fortiguard.fortinet.com/psirt/FG-IR-26-112, accessed June 16, 2026.
  2. Fortinet, “OS Command Injection vulnerability in FortiSandbox,” FortiGuard PSIRT FG-IR-26-100, April 14, 2026, https://fortiguard.fortinet.com/psirt/FG-IR-26-100, accessed June 16, 2026.
  3. Fortinet, “OS Command Injection vulnerability in FortiSandbox WEB UI,” FortiGuard PSIRT FG-IR-26-141, June 9, 2026, https://fortiguard.fortinet.com/psirt/FG-IR-26-141, accessed June 16, 2026.
  4. Sergiu Gatlan, “Critical Fortinet FortiSandbox flaws now exploited in attacks,” BleepingComputer, June 16, 2026, https://www.bleepingcomputer.com/news/security/critical-fortinet-fortisandbox-flaws-now-exploited-in-attacks/, accessed June 16, 2026.
  5. The Hacker News, “Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week,” June 16, 2026, https://thehackernews.com/2026/06/attackers-exploit-three-fortinet.html, accessed June 16, 2026.
  6. Defused Cyber, X post on FortiSandbox exploitation observations, June 15, 2026, https://x.com/DefusedCyber/status/2066575288503255274, accessed June 16, 2026.

Tags:

CVEVulnerability
Author

ogwatermelon

Follow Me
Other Articles
Previous

UNC6508 Abuses Google Workspace Rules to Steal US Medical and Defense Research

Next

Mastra npm Supply Chain Attack: 144 Packages Compromised

AI Botnet Breach CVE Exploit Hack Incident Linux Malware Network Ransomware supply chain Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Linux
  • Malware
  • Phishing
  • Ransomware
  • supply-chain
  • Uncategorized
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.