Recent developments have emerged regarding two critical vulnerabilities in FortiSandbox, confirmed by the Cybersecurity and Infrastructure Security Agency (CISA) as being actively exploited. The vulnerabilities, identified as CVE-2026-39808 and CVE-2026-25089, both carry a CVSS score of 9.1 and affect FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS.
Details of the Vulnerabilities
According to Fortinet, these vulnerabilities are classified as OS command injection flaws. They allow unauthenticated attackers to execute arbitrary commands through specially crafted HTTP requests, which do not require valid credentials or user interaction. This raises significant concerns regarding the potential for remote code execution through relatively low-complexity attacks.
Patch Status and Exploitation
Fortinet has released patches for these vulnerabilities, with CVE-2026-39808 addressed in April and CVE-2026-25089 in June. Despite the availability of these fixes, Fortinet has not publicly acknowledged that either vulnerability is being exploited in the wild. However, CISA has included both vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog, indicating that there is evidence of active exploitation.
Implications for Federal Agencies
For federal civilian agencies, vulnerabilities listed in the KEV catalog are subject to Binding Operational Directive 26-04, which mandates that these organizations must apply patches by specified deadlines or discontinue the use of affected products if they cannot be secured adequately.
Additional Observations
Security firm Defused has also reported observing exploitation attempts against these vulnerabilities, alongside another related vulnerability, CVE-2026-39813. However, it noted that not all exploitation attempts appear successful, describing one targeting CVE-2026-25089 as “vibecoded” and likely broken, with no confirmed working public exploit available at this time.
As organizations assess their security posture, the urgency to address these vulnerabilities is underscored by CISA’s recent updates and the ongoing threat landscape surrounding Fortinet products.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








