CISA Confirmed Two FortiSandbox Exploits. A Third Was Reported a Month Earlier.
CISA has confirmed active exploitation of two unauthenticated command-injection vulnerabilities in FortiSandbox, the product designed to isolate and analyse suspicious files. A third vulnerability in the same platform was reported under exploitation a month earlier but was not included in the federal catalogue.
The confirmed entries are CVE-2026-39808 and CVE-2026-25089. CISA added both to its Known Exploited Vulnerabilities catalogue on 16 July 2026. Threat-intelligence firm Defused had already reported observed exploitation of those flaws and the related authentication bypass CVE-2026-39813 on 16 June.
The distinction matters. CISA’s listing is government confirmation for two vulnerabilities. The third rests on Defused’s observation, repeated by multiple reliable security publications, without equivalent CISA confirmation. Fortinet’s individual advisory pages still displayed “Known Exploited: No” when checked, creating a public-status lag defenders should not mistake for evidence that exploitation is absent.
Three vulnerabilities expose two command paths and an authentication boundary
CVE-2026-39808 is an unauthenticated operating-system command injection in the FortiSandbox API. Fortinet assigns it a critical CVSS score of 9.1. The flaw affects FortiSandbox 4.4.0 through 4.4.8 and is fixed in 4.4.9 or later. Fortinet says FortiSandbox 5.0 and FortiSandbox PaaS 5.0 are not affected by this specific issue.
CVE-2026-25089 is a separate second-order command injection in the web interface’s VNC-start feature. A remote unauthenticated attacker can place malicious JSON input that is later used in an operating-system command. It affects on-premises, cloud and PaaS deployments in the version ranges listed by Fortinet.
For that flaw, affected on-premises FortiSandbox 5.0.0 through 5.0.5 must move to 5.0.6 or later, while 4.4.0 through 4.4.8 must move to 4.4.9 or later. FortiSandbox Cloud and PaaS 5.0.4 through 5.0.5 must move to 5.0.6 or later. FortiSandbox 5.2, Cloud 5.2 and the listed 4.4 Cloud and PaaS branches are not affected.
CVE-2026-39813 is a path-traversal vulnerability in the JRPC API that lets an unauthenticated attacker bypass authentication through crafted HTTP requests. Fortinet describes the impact as privilege escalation and assigns the flaw a critical score of 9.1. FortiSandbox 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8 are affected; the fixed releases are 5.0.6 and 4.4.9.
The security control is also an integration hub
FortiSandbox is not a disposable analysis workstation. It can receive files and URLs from FortiGate, FortiMail, FortiProxy and other controls, then return verdicts that drive blocking and automated responses. That position makes the management and API surfaces unusually sensitive. Code execution on the sandbox can expose integrations, credentials, samples, verdict flows and trusted network paths.
Public reporting did not identify the attackers, victims or post-exploitation actions. One exploit observed for CVE-2026-25089 was described as AI-generated and likely faulty. That is evidence of attempted exploitation and rapid tool construction, not proof that every attempt succeeded or that a particular actor used artificial intelligence effectively.
What defenders should do now
- Inventory FortiSandbox appliances, cloud tenants and PaaS deployments, including versions and exposed management or API interfaces.
- Apply the fixed release for every affected branch. Do not assume one upgrade covers a differently managed cloud or PaaS instance.
- Restrict web, API and JRPC access to dedicated management networks and trusted administrators.
- Review web and API telemetry from at least 15 June 2026 for crafted HTTP requests, unusual VNC-start activity, authentication anomalies and command execution.
- Investigate unexpected verdict changes, integration-token use, outbound connections and access to submitted samples.
- If exploitation is suspected, treat the appliance as a compromised security-control host, rotate connected credentials and validate downstream trust relationships.
The larger lesson is uncomfortable but useful. Sandboxes are built to handle hostile content, yet the surrounding control plane can still become an attack surface. When an attacker can reach that plane without credentials, the product intended to contain malware may instead provide access to the systems that act on its decisions.
Sources: Fortinet PSIRT advisories FG-IR-26-100 and FG-IR-26-112 (14 April 2026; no publication time provided), and FG-IR-26-141 (9 June 2026; no publication time provided); BleepingComputer (16 June 2026 at 05:19); Canadian Centre for Cyber Security advisory AV26-351 (initially 14 April 2026, updated 16 July 2026; no times provided); and CISA Known Exploited Vulnerabilities catalogue (entries added 16 July 2026; no publication time provided).


