VulnerabilityBleeping Computer
9.8 — CRITICAL
Critical Fortinet FortiSandbox flaws now exploited in attacks
Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Attackers are exploiting multiple critical vulnerabilities in Fortinet's FortiSandbox platform, allowing them to escalate privileges and execute unauthorized code remotely through low-complexity command injection attacks. This is the latest in a series of Fortinet security flaws exploited in ransomware attacks and cyber espionage campaigns.
⚙️Technical Details
CVEs
CVE-2026-39813CVE-2026-39808CVE-2026-25089
Affected Systems
Fortinet FortisandboxFortinet Fortisandbox CloudFortinet Fortisandbox PaaS
Attack Vectors
NETWORK, LOW
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Organizations using Fortinet's FortiSandbox platform, particularly those in the finance and healthcare sectors.
🛡️Recommended Actions
1Immediately upgrade affected deployments to the latest released versions of Fortinet's FortiSandbox platform.
2Implement additional security measures, such as network segmentation and intrusion detection systems, to prevent lateral movement.
3Monitor for signs of exploitation and implement incident response plans to quickly respond to potential attacks.
📦Affected Products
Fortinet FortisandboxFortinet Fortisandbox CloudFortinet Fortisandbox PaasFortinet FortiosFortinet FortipamFortinet FortiproxyFortinet FortiswitchmanagerFortinet Fortisandbox PaaS
🔐NVD Verified DataVERIFIED
CVE-2026-39813 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-24
Affected Products (CPE)
Fortinet Fortisandbox
CVE-2026-39808 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-78
Affected Products (CPE)
Fortinet Fortisandbox
CVE-2026-25089 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-78
Affected Products (CPE)
Fortinet FortisandboxFortinet Fortisandbox CloudFortinet Fortisandbox Paas
CVE-2025-61624 ↗CVSS 6.5 — MEDIUM
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:HWeaknesses
CWE-22
Affected Products (CPE)
Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortiswitchmanager
CVE-2026-26083 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-862
Affected Products (CPE)
Fortinet FortisandboxFortinet Fortisandbox CloudFortinet Fortisandbox Paas
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
