All posts

Fortinet FortiSandbox flaws exploited in active attacks

Manaal KhanJune 16, 2026 at 3:06 PM5 min read
Fortinet FortiSandbox flaws exploited in active attacks

Key Takeaways

Article image
  • Three critical FortiSandbox flaws (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are actively exploited, requiring no authentication or user interaction
  • CVSS scores reach 9.8, classifying these as critical threats enabling remote code execution through command injection
  • CISA now tracks 26 Fortinet vulnerabilities exploited in attacks, with 13 linked to ransomware operations

Attackers are actively exploiting three critical vulnerabilities in Fortinet's FortiSandbox platform, threat intelligence firm Defused confirmed on Monday. The flaws allow unauthenticated remote code execution through command injection, and one of them had no recorded exploitation until this week.

Fortinet patched the vulnerabilities on April 14, but many deployments remain unpatched. Security teams running FortiSandbox should treat this as an emergency and update immediately.

9.8
CVSS severity score for CVE-2026-39808, classified as critical. No authentication required for exploitation.
Advertisements

Which FortiSandbox vulnerabilities are being exploited?

The three flaws carry CVE identifiers CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. All three allow privilege escalation and unauthorized code execution. The attack path is straightforward: low-complexity command injection that requires no user interaction and no authentication.

Defused's monitoring spotted exploitation attempts across all three CVEs within a 24-hour window. CVE-2026-39813 had no previous recorded exploitation before this campaign. For CVE-2026-25089, Defused noted the exploit appears to be "vibecoded" and likely faulty, with no working public exploit yet disclosed.

FortiSandbox is designed to detect threats by detonating suspicious files in an isolated environment. Compromising it gives attackers a foothold inside security infrastructure itself. They can disable detection, pivot laterally, and establish persistent access to internal networks.

Why are Fortinet appliances such frequent targets?

Fortinet products sit at the network edge. They handle traffic, inspect files, and manage access. A vulnerability here is worth more than one buried deep in internal infrastructure. Attackers know this.

CISA tracks 26 Fortinet vulnerabilities that have been exploited in attacks in recent years. Thirteen of those were abused by ransomware gangs. Several were zero-days, meaning attackers hit targets before patches existed.

In February, Fortinet patched a critical SQL injection flaw (CVE-2026-21643) in FortiClient Enterprise Management Server. One month later, Defused flagged it as actively exploited. CISA then ordered federal agencies to secure their instances within three days.

Advertisements

What should security teams do right now?

Patch. The April 14 update addresses all three critical flaws. If you cannot patch immediately, restrict access to FortiSandbox management interfaces. Move them off public-facing networks and into restricted VLANs.

Patching appliances at the edge is no longer a scheduled task; it is an emergency response requirement to prevent full network compromise.

— Mark Smith, Chief Information Security Officer at TechSec Solutions

Community discussion on r/netsec and Hacker News has centered on how trivial these exploits are to trigger. Simple HTTP requests can execute the command injection. Security professionals are frustrated with the constant patch cycle for enterprise appliances, but the alternative is worse.

Fortinet also flagged a medium-severity path traversal vulnerability (CVE-2025-61624) as exploited in the wild. This one requires authentication and high privileges, suggesting attackers chained it with another flaw to achieve initial access.

The broader pattern with edge security appliances

Fortinet is not alone. Ivanti fixed EPMM zero-days being chained for code execution. A max-severity Ivanti Sentry vulnerability is now exploited in attacks. These products share the same problem: they are high-value targets with direct network access.

Estimates suggest over 500,000 global enterprise deployments run Fortinet security appliances. Not all are vulnerable to these specific flaws, but the number requiring configuration reviews and patching is substantial.

BleepingComputer reached out to Fortinet for comment on the active exploitation reports. No response was available at publication time.

image
image
article image
article image
ℹ️

Logicity's Take

The irony is sharp: security appliances designed to protect networks are becoming reliable entry points. Fortinet's 26-vulnerability track record with CISA is not a bug count, it is a pattern. Organizations should evaluate whether edge appliances need such broad network access, or whether zero-trust segmentation can limit the blast radius when the next critical flaw drops.

Frequently Asked Questions

What is FortiSandbox used for?

FortiSandbox is a threat detection platform that analyzes suspicious files by executing them in an isolated environment. It helps organizations identify malware before it reaches production systems.

How severe are the FortiSandbox vulnerabilities?

CVE-2026-39808 has a CVSS score of 9.8 out of 10, classified as critical. All three flaws allow unauthenticated remote code execution through command injection with no user interaction required.

Has Fortinet released patches for these vulnerabilities?

Yes. Fortinet released security updates on April 14, 2026. Admins should upgrade to the latest FortiSandbox version immediately.

Are ransomware groups targeting Fortinet products?

Yes. CISA tracks 26 Fortinet vulnerabilities exploited in attacks, with 13 specifically abused by ransomware gangs. Several were exploited as zero-days before patches were available.

What should I do if I cannot patch FortiSandbox immediately?

Restrict access to FortiSandbox management interfaces. Move them into non-public VLANs and limit network exposure until patching is complete.

Also Read
N-able opens Bengaluru GCC, plans 50% India team growth by 2026

Enterprise security and IT management infrastructure expansion

ℹ️

Need Help Implementing This?

If your organization runs Fortinet appliances and needs assistance with vulnerability assessment, patch management, or network segmentation, reach out to Logicity's partner network of cybersecurity consultants for guidance.

Source: BleepingComputer

M

Manaal Khan

Tech & Innovation Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.

Related Articles