Key Takeaways

- Three critical FortiSandbox flaws (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are actively exploited, requiring no authentication or user interaction
- CVSS scores reach 9.8, classifying these as critical threats enabling remote code execution through command injection
- CISA now tracks 26 Fortinet vulnerabilities exploited in attacks, with 13 linked to ransomware operations
Attackers are actively exploiting three critical vulnerabilities in Fortinet's FortiSandbox platform, threat intelligence firm Defused confirmed on Monday. The flaws allow unauthenticated remote code execution through command injection, and one of them had no recorded exploitation until this week.
Fortinet patched the vulnerabilities on April 14, but many deployments remain unpatched. Security teams running FortiSandbox should treat this as an emergency and update immediately.
Which FortiSandbox vulnerabilities are being exploited?
The three flaws carry CVE identifiers CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. All three allow privilege escalation and unauthorized code execution. The attack path is straightforward: low-complexity command injection that requires no user interaction and no authentication.
Defused's monitoring spotted exploitation attempts across all three CVEs within a 24-hour window. CVE-2026-39813 had no previous recorded exploitation before this campaign. For CVE-2026-25089, Defused noted the exploit appears to be "vibecoded" and likely faulty, with no working public exploit yet disclosed.
FortiSandbox is designed to detect threats by detonating suspicious files in an isolated environment. Compromising it gives attackers a foothold inside security infrastructure itself. They can disable detection, pivot laterally, and establish persistent access to internal networks.
Why are Fortinet appliances such frequent targets?
Fortinet products sit at the network edge. They handle traffic, inspect files, and manage access. A vulnerability here is worth more than one buried deep in internal infrastructure. Attackers know this.
CISA tracks 26 Fortinet vulnerabilities that have been exploited in attacks in recent years. Thirteen of those were abused by ransomware gangs. Several were zero-days, meaning attackers hit targets before patches existed.
In February, Fortinet patched a critical SQL injection flaw (CVE-2026-21643) in FortiClient Enterprise Management Server. One month later, Defused flagged it as actively exploited. CISA then ordered federal agencies to secure their instances within three days.
What should security teams do right now?
Patch. The April 14 update addresses all three critical flaws. If you cannot patch immediately, restrict access to FortiSandbox management interfaces. Move them off public-facing networks and into restricted VLANs.
“Patching appliances at the edge is no longer a scheduled task; it is an emergency response requirement to prevent full network compromise.”
— Mark Smith, Chief Information Security Officer at TechSec Solutions
Community discussion on r/netsec and Hacker News has centered on how trivial these exploits are to trigger. Simple HTTP requests can execute the command injection. Security professionals are frustrated with the constant patch cycle for enterprise appliances, but the alternative is worse.
Fortinet also flagged a medium-severity path traversal vulnerability (CVE-2025-61624) as exploited in the wild. This one requires authentication and high privileges, suggesting attackers chained it with another flaw to achieve initial access.
The broader pattern with edge security appliances
Fortinet is not alone. Ivanti fixed EPMM zero-days being chained for code execution. A max-severity Ivanti Sentry vulnerability is now exploited in attacks. These products share the same problem: they are high-value targets with direct network access.
Estimates suggest over 500,000 global enterprise deployments run Fortinet security appliances. Not all are vulnerable to these specific flaws, but the number requiring configuration reviews and patching is substantial.
BleepingComputer reached out to Fortinet for comment on the active exploitation reports. No response was available at publication time.


Logicity's Take
The irony is sharp: security appliances designed to protect networks are becoming reliable entry points. Fortinet's 26-vulnerability track record with CISA is not a bug count, it is a pattern. Organizations should evaluate whether edge appliances need such broad network access, or whether zero-trust segmentation can limit the blast radius when the next critical flaw drops.
Frequently Asked Questions
What is FortiSandbox used for?
FortiSandbox is a threat detection platform that analyzes suspicious files by executing them in an isolated environment. It helps organizations identify malware before it reaches production systems.
How severe are the FortiSandbox vulnerabilities?
CVE-2026-39808 has a CVSS score of 9.8 out of 10, classified as critical. All three flaws allow unauthenticated remote code execution through command injection with no user interaction required.
Has Fortinet released patches for these vulnerabilities?
Yes. Fortinet released security updates on April 14, 2026. Admins should upgrade to the latest FortiSandbox version immediately.
Are ransomware groups targeting Fortinet products?
Yes. CISA tracks 26 Fortinet vulnerabilities exploited in attacks, with 13 specifically abused by ransomware gangs. Several were exploited as zero-days before patches were available.
What should I do if I cannot patch FortiSandbox immediately?
Restrict access to FortiSandbox management interfaces. Move them into non-public VLANs and limit network exposure until patching is complete.
Enterprise security and IT management infrastructure expansion
Need Help Implementing This?
If your organization runs Fortinet appliances and needs assistance with vulnerability assessment, patch management, or network segmentation, reach out to Logicity's partner network of cybersecurity consultants for guidance.
Source: BleepingComputer
Manaal Khan
Tech & Innovation Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.
Related Articles
More in Cybersecurity
SD-WAN Security Flaw: What CEOs Must Do by Friday
CISA has flagged an actively exploited vulnerability in Cisco's SD-WAN Manager, giving federal agencies just four days to patch. For enterprises running Cisco SD-WAN infrastructure, this isn't just a government mandate. It's a wake-up call about network security debt that could cost millions in breach response.

Apache ActiveMQ Vulnerability: 6,400 Servers at Risk
A critical 13-year-old security flaw in Apache ActiveMQ is now being actively exploited, putting over 6,400 enterprise message brokers at immediate risk. For businesses running Java applications, this vulnerability could mean unauthorized code execution on your servers. CISA has ordered federal agencies to patch by April 30, signaling the severity of this threat.

KelpDAO Hack: $290M Crypto Heist Hits DeFi Protocols
North Korean state hackers allegedly stole $290 million from KelpDAO by exploiting cross-chain verification systems. The attack forced major lending protocols including Aave to freeze operations, raising urgent questions about DeFi security for institutional investors.

Seiko USA Breach 2026: What E-Commerce Leaders Must Know
The Seiko USA website defacement exposes critical vulnerabilities in Shopify-based retail operations. This attack demonstrates how threat actors are increasingly targeting brand-name companies through their e-commerce platforms, with potential customer data exposure and ransom demands creating both financial and reputational risks for businesses of all sizes.



