Back to Blog
CVE-2026-39813, CVE-2026-39808, CVE-2026-25089: Fortinet FortiSandbox — Unauthenticated RCE in Active Exploitation (June 2026)
vulnerabilities

CVE-2026-39813, CVE-2026-39808, CVE-2026-25089: Fortinet FortiSandbox — Unauthenticated RCE in Active Exploitation (June 2026)

breachwire TeamJun 17, 20262 min read

CVE-2026-39813, CVE-2026-39808, CVE-2026-25089 — Fortinet FortiSandbox

Three critical vulnerabilities—CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089—affect Fortinet’s FortiSandbox product. All three allow unauthenticated attackers to execute arbitrary code remotely via specially crafted HTTP requests. These flaws are rated critical and are confirmed to be actively exploited in the wild within 24 hours of patch release, underscoring immediate risk.

Attack Vector

Attackers exploit these vulnerabilities by sending maliciously crafted HTTP requests to exposed FortiSandbox instances. No authentication is required, and exploitation leads directly to remote code execution with system-level privileges. The attack does not require user interaction or pre-existing access. Rapid exploitation post-patch release highlights automated scanning and exploitation by threat actors. No specific IOCs are provided, but network logs may show anomalous HTTP POST or GET requests targeting FortiSandbox endpoints.

Who Is at Risk

All organizations deploying Fortinet FortiSandbox appliances are at risk, regardless of deployment type (on-premises or cloud-managed). Any unpatched system is vulnerable. Fortinet is the affected vendor; no other vendors are implicated. Exploitation is global in scope.

Patch & Mitigate

  • Patch: Apply the latest FortiSandbox security updates for CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 immediately. Reference Fortinet’s official advisory for exact versions.
  • Workaround: If patching is not immediately possible, restrict network access to FortiSandbox management interfaces and monitor for suspicious HTTP traffic.
  • Detect: Review HTTP access logs for unusual or unauthorized requests to FortiSandbox endpoints, especially those lacking authentication headers. Monitor for unexpected process launches on FortiSandbox appliances.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers gain access via exposed FortiSandbox HTTP interfaces.
  • TA0005 — Defense Evasion: Exploitation may allow attackers to bypass authentication and logging controls.
  • TA0009 — Collection: Full system compromise enables attackers to access sensitive sandboxed data.

Source: https://securityaffairs.com/193709/ai/fortinet-warned-as-three-critical-fortisandbox-bugs-come-under-attack.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: