The US cybersecurity agency has ordered federal departments to patch two critical FortiSandbox vulnerabilities by Sunday, July 19.
Attackers are actively exploiting both security flaws. They can abuse them to execute unauthorized commands on vulnerable Fortinet systems without authentication.
The affected platform helps organizations detect and analyze suspicious files. Therefore, a successful attack could compromise a security product designed to defend corporate and government networks.
Two Critical FortiSandbox Flaws Under Attack
The vulnerabilities are tracked as CVE-2026-39808 and CVE-2026-25089. Both involve OS command injection and carry critical severity ratings.
An attacker can exploit the flaws by sending specially crafted HTTP requests to an exposed system. The attack has low technical complexity. It also requires no account, password, or user interaction.
Successful exploitation allows criminals to run unauthorized code or operating system commands remotely. As a result, an attacker could potentially take control of the affected appliance.
Fortinet addressed CVE-2026-39808 on April 14, 2026. The company later patched CVE-2026-25089 on June 9.
CISA Adds Flaws to Exploited Vulnerability List
The Cybersecurity and Infrastructure Security Agency added both FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities catalog on July 16.
This catalog contains security flaws with confirmed evidence of exploitation. Federal agencies must address listed vulnerabilities within the deadlines set by CISA.
Under Binding Operational Directive 26-04, agencies must patch affected FortiSandbox installations by July 19. If a suitable fix is unavailable, they may need to stop using the vulnerable product.
Although the order applies directly to US federal agencies, private companies should also act quickly. Security teams often use the catalog to prioritize vulnerabilities that pose an immediate threat.
Researchers Detected Exploitation in June
A threat intelligence company first reported active attacks involving the vulnerabilities in June. Its researchers observed criminals targeting several FortiSandbox flaws over a 24-hour period.
The attacks reportedly involved CVE-2026-39808 and CVE-2026-25089. Researchers also detected attempts to exploit CVE-2026-39813, a separate vulnerability affecting the same platform.
Fortinet had not initially marked the two command injection flaws as exploited in the wild. However, CISA has now confirmed active exploitation.
The agency has not revealed who is behind the attacks. It has also not disclosed how many systems have been compromised.
CVE-2026-25089 Affects Several Fortinet Products
CVE-2026-25089 affects the web interfaces of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS.
The flaw results from unsafe handling of special characters in operating system commands. Consequently, an unauthenticated attacker can insert malicious instructions into crafted web requests.
Affected FortiSandbox installations should move to a fixed release. Fortinet recommends upgrading version 5.0 deployments to 5.0.6 or later. Meanwhile, version 4.4 users should install 4.4.9 or later.
FortiSandbox 5.2 and FortiSandbox Cloud 5.2 are not affected by this vulnerability.
Administrators Must Install the Latest Updates
Fortinet customers should upgrade all affected deployments to the newest available release. Patching closes the known vulnerabilities and blocks the documented exploitation methods.
However, installing updates may not be enough if attackers have already breached a system. Administrators should also review logs, configuration changes, and network activity for signs of unauthorized access.
Security teams should pay particular attention to unexpected commands, new accounts, unusual outbound connections, and changes to system settings.
Furthermore, management interfaces should not remain exposed to the public internet unless absolutely necessary. Restricting access can reduce the number of attackers able to reach a vulnerable appliance.
Fortinet Products Remain Popular Targets
Attackers frequently target Fortinet products because they often sit at important points within corporate networks. Compromising one of these systems may provide access to internal infrastructure or sensitive traffic.
CISA currently tracks 28 exploited Fortinet vulnerabilities in its catalog. Attackers have also used 13 of those flaws during ransomware incidents.
Earlier in 2026, Fortinet patched other vulnerabilities that later appeared in active attacks. These included a critical SQL injection flaw in FortiClient Enterprise Management Server and a path traversal weakness that allowed privilege escalation.
The latest warning shows why organizations must prioritize security updates for internet-facing products. With the FortiSandbox vulnerabilities now under active attack, delayed patching could leave systems exposed to remote compromise.


0 responses to “FortiSandbox Vulnerabilities Exploited in Active Attacks”