FeedVulnerabilityCritical Fortinet FortiSandbox flaws now exploited in attack...
VulnerabilityBleeping Computer
9.8CRITICAL

Critical Fortinet FortiSandbox flaws now exploited in attacks

📅 16 June 2026 at 09:19 UTC📰 Bleeping ComputerView original source ↗
Critical Fortinet FortiSandbox flaws now exploited in attacks

Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Attackers are exploiting multiple critical vulnerabilities in Fortinet's FortiSandbox platform, allowing them to escalate privileges and execute unauthorized code remotely through low-complexity command injection attacks. This is the latest in a series of Fortinet security flaws exploited in ransomware attacks and cyber espionage campaigns.

⚙️Technical Details
CVEs
CVE-2026-39813CVE-2026-39808CVE-2026-25089
Affected Systems
Fortinet FortisandboxFortinet Fortisandbox CloudFortinet Fortisandbox PaaS
Attack Vectors
NETWORK, LOW
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Organizations using Fortinet's FortiSandbox platform, particularly those in the finance and healthcare sectors.
🛡️Recommended Actions
1Immediately upgrade affected deployments to the latest released versions of Fortinet's FortiSandbox platform.
2Implement additional security measures, such as network segmentation and intrusion detection systems, to prevent lateral movement.
3Monitor for signs of exploitation and implement incident response plans to quickly respond to potential attacks.
📦Affected Products
Fortinet FortisandboxFortinet Fortisandbox CloudFortinet Fortisandbox PaasFortinet FortiosFortinet FortipamFortinet FortiproxyFortinet FortiswitchmanagerFortinet Fortisandbox PaaS
🔐NVD Verified DataVERIFIED
CVE-2026-39813CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-24
Affected Products (CPE)
Fortinet Fortisandbox
CVE-2026-39808CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected Products (CPE)
Fortinet Fortisandbox
CVE-2026-25089CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected Products (CPE)
Fortinet FortisandboxFortinet Fortisandbox CloudFortinet Fortisandbox Paas
CVE-2025-61624CVSS 6.5MEDIUM
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Weaknesses
CWE-22
Affected Products (CPE)
Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortiswitchmanager
CVE-2026-26083CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-862
Affected Products (CPE)
Fortinet FortisandboxFortinet Fortisandbox CloudFortinet Fortisandbox Paas

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed