Attackers exploit three Fortinet FortiSandbox flaws at once, threatening security verdict engine
Threat-intel firm Defused reports active exploitation of three patched FortiSandbox bugs, including a newly hit critical authentication-bypass flaw; Fortinet has not confirmed the attacks.
Attackers have been exploiting three vulnerabilities in Fortinet FortiSandbox simultaneously, the threat intelligence firm Defused reported on June 16, 2026, citing activity within the prior 24 hours. Fortinet had not independently confirmed in-the-wild exploitation as of publication.
The most severe is CVE-2026-39813, a critical path-traversal flaw in FortiSandbox's JRPC API that can be leveraged to bypass authentication on affected systems. Defused said it had recorded no prior in-the-wild exploitation of that flaw. The other two are CVE-2026-39808, an OS command injection that can lead to unauthenticated code or command execution, and CVE-2026-25089, an OS command injection in the FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS web interface that allows an unauthenticated attacker to run unauthorized commands via crafted HTTP requests. Fortinet disclosed CVE-2026-39813 and CVE-2026-39808 in April 2026 and disclosed CVE-2026-25089 on June 9, 2026.
CVE-2026-25089 was discovered by Adham El Karn of the Fortinet Product Security team, the advisory said. Defused noted that the exploit for that flaw appears to be AI-generated and likely faulty, and that no working exploit has been publicly disclosed.
All three flaws are patched, and no specific threat actor has been attributed. A FortiSandbox compromise carries outsized risk because the platform issues the verdicts that drive security enforcement across an entire Fortinet deployment. The exploitation claims rest on a single threat-intelligence source and remain unconfirmed by Fortinet; administrators on affected versions should apply the available fixes.
Founder and Chief Editor of Data Phoenix — a San Francisco Bay Area media and education platform focused on AI and Data.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
