
Attention Fortinet FortiSandbox Users! CISA Warns of Critical Vulnerabilities Actively Exploited in Real-World Cyberattacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two dangerous vulnerabilities affecting the Fortinet FortiSandbox platform to its Known Exploited Vulnerabilities (KEV) Catalog. This indicates that these vulnerabilities are being actively exploited by cybercriminals in real-world attacks.
According to security experts, if successfully exploited, these vulnerabilities could allow attackers to execute arbitrary operating system commands remotely without authentication, bypass security mechanisms, and gain complete control over affected systems.
Which Vulnerabilities Were Identified?
The actively exploited vulnerabilities are:
- CVE-2026-39808
- CVE-2026-25089
Both vulnerabilities are classified as OS Command Injection (CWE-78) flaws. They occur because user-supplied input is not properly validated before being passed to operating system commands.
As a result, an attacker can send specially crafted HTTP requests to execute malicious commands on the target system.
How Do These Vulnerabilities Work?
CVE-2026-39808
This vulnerability specifically affects Fortinet FortiSandbox.
By sending specially crafted HTTP requests, an attacker can:
- Exploit the system without authentication;
- Execute the attack without administrator privileges;
- Require no user interaction;
and execute arbitrary commands at the operating system level.
This could ultimately allow an attacker to gain complete control over the server.
CVE-2026-25089
The second vulnerability has a broader impact and affects:
- FortiSandbox
- FortiSandbox Cloud
- FortiSandbox PaaS
Like the first vulnerability, it can be exploited remotely using specially crafted HTTP requests, allowing attackers to execute arbitrary operating system commands.
Why Are These Vulnerabilities Dangerous?
FortiSandbox is widely used in enterprise environments to analyze the following within an isolated sandbox environment:
- Malicious files;
- Email attachments;
- URLs;
- Exploits;
- Unknown applications.
It is also commonly integrated with other Fortinet security solutions, including:
- FortiGate
- FortiMail
- FortiEDR
- FortiSIEM
- FortiAnalyzer
Because of these integrations, compromising a FortiSandbox system could jeopardize not only a single server but an organization’s entire cybersecurity infrastructure.
According to security experts, attackers exploiting these vulnerabilities could:
- Deploy web shells;
- Install malware;
- Obtain administrator privileges;
- Steal user credentials;
- Move laterally across the network;
- Disable security controls;
- Prepare the environment for ransomware attacks.
Why Did CISA Add Them to the KEV Catalog?
On July 16, 2026, CISA added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog.
Only vulnerabilities that:
- Are actively exploited in real-world cyberattacks;
- Pose a significant risk to organizations;
- Require immediate remediation;
are included in the KEV Catalog.
This confirms that these vulnerabilities are not merely theoretical—they are actively being exploited by threat actors.
As a result, U.S. Federal Civilian Executive Branch (FCEB) agencies have been directed to apply the required security updates within the deadlines established by Binding Operational Directive (BOD) 26-04.
What Should Organizations Do?
Cybersecurity experts recommend that organizations:
- Immediately install all security updates released by Fortinet;
- Identify FortiSandbox servers exposed to the Internet;
- Restrict external access to management interfaces;
- Analyze HTTP logs for unusual or suspicious HTTP requests;
- Check whether unexpected operating system commands have been executed;
- Verify that no unauthorized administrator accounts or new users have been created;
- Confirm that FortiSandbox Cloud and FortiSandbox PaaS instances are fully updated;
- If indicators of compromise are identified, perform the forensic triage procedures recommended by CISA.
If security updates cannot be installed immediately, organizations should temporarily discontinue the use of affected services until appropriate mitigations are implemented or the vulnerabilities are fully addressed by the vendor.
The CVE-2026-39808 and CVE-2026-25089 vulnerabilities affecting Fortinet FortiSandbox are among the most dangerous security flaws currently being actively exploited in real-world cyberattacks. These vulnerabilities enable attackers to execute arbitrary operating system commands without authentication, bypass security mechanisms, and establish deep access within enterprise environments.
Because FortiSandbox is a critical component of enterprise cybersecurity architecture, delaying remediation could expose an organization’s entire network to significant risk. Organizations using Fortinet FortiSandbox are strongly advised to install Fortinet’s security updates without delay, reassess Internet-facing systems, and conduct comprehensive investigations for any indicators of compromise.



