CISA Confirms Active Exploitation of Critical FortiSandbox Vulnerabilities

CISA has confirmed that two critical vulnerabilities in FortiSandbox are being actively exploited, prompting urgent action from affected organizations.

Recent developments have emerged regarding two critical vulnerabilities in FortiSandbox, confirmed by the Cybersecurity and Infrastructure Security Agency (CISA) as being actively exploited. The vulnerabilities, identified as CVE-2026-39808 and CVE-2026-25089, both carry a CVSS score of 9.1 and affect FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS.

Details of the Vulnerabilities

According to Fortinet, these vulnerabilities are classified as OS command injection flaws. They allow unauthenticated attackers to execute arbitrary commands through specially crafted HTTP requests, which do not require valid credentials or user interaction. This raises significant concerns regarding the potential for remote code execution through relatively low-complexity attacks.

Patch Status and Exploitation

Fortinet has released patches for these vulnerabilities, with CVE-2026-39808 addressed in April and CVE-2026-25089 in June. Despite the availability of these fixes, Fortinet has not publicly acknowledged that either vulnerability is being exploited in the wild. However, CISA has included both vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog, indicating that there is evidence of active exploitation.

Implications for Federal Agencies

For federal civilian agencies, vulnerabilities listed in the KEV catalog are subject to Binding Operational Directive 26-04, which mandates that these organizations must apply patches by specified deadlines or discontinue the use of affected products if they cannot be secured adequately.

Additional Observations

Security firm Defused has also reported observing exploitation attempts against these vulnerabilities, alongside another related vulnerability, CVE-2026-39813. However, it noted that not all exploitation attempts appear successful, describing one targeting CVE-2026-25089 as “vibecoded” and likely broken, with no confirmed working public exploit available at this time.

As organizations assess their security posture, the urgency to address these vulnerabilities is underscored by CISA’s recent updates and the ongoing threat landscape surrounding Fortinet products.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 316