INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Fortinet FortiSandbox Vulnerability Exploited in Attacks

| 2026-06-16 09:19 CRITICAL HIGH
Executive Summary AI-generated
Fortinet's latest FortiSandbox vulnerabilities have been exploited in the wild, with three critical flaws - CVE-2026-39813, CVE-2026-39808 and CVE-2026-25089 - being actively targeted by attackers. The third flaw,CVE-2026-39813, is a path traversal vulnerability that could allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests. This has raised concerns among cybersecurity experts who speculate about the potential use of artificial intelligence in developing exploits for these vulnerabilities.
Technical Mitigations AI-generated
* Implement a robust patch management strategy, including regular updates and testing of Fortinet gear to ensure timely patches for critical vulnerabilities. * Use secure coding practices and input validation to prevent OS command injection attacks like CVE-2026-25089. * Regularly monitor system logs and network traffic for signs of exploitation or suspicious activity related to FortiSandbox flaws. * Consider implementing a sandboxing solution, such as a virtual machine or containerization platform, to isolate vulnerable systems from potential attackers.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-39813CVE-2026-39813 CVE-2025-61624CVE-2025-61624 CVE-2026-39808CVE-2026-39808 CVE-2026-35616CVE-2026-35616 CVE-2026-21643CVE-2026-21643 CVE-2026-25089CVE-2026-25089 CVE-2026-26083CVE-2026-26083
Target & Sectors
Global Scope
Incident Timeline
‎April 13
Threat actors exploited the CVE-2026-21643 flaw in FortiClient EMS instances.
vulnerability CVE-2026-21643
attribution FortiClient EMS
‎April 14
Threat actors exploited the Fortinet FortiSandbox vulnerabilities CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 in attacks targeting systems on April 14.
vulnerability CVE-2026-39813
vulnerability CVE-2026-39808
vulnerability CVE-2026-25089
‎April 2026
Threat actors exploited a critical Fortinet FortiSandbox flaw in the wild.
general_metric 9.1 second flaw
infrastructure 9.1
vulnerability CVE-2026-35616
organisation FortiClient EMS
organisation CVSS
organisation Fortinet
‎2026/06/09
Threat actors used a previously patched CVE-2026-25089 vulnerability in FortiSandbox to target the affected software.
organisation Fortinet FortiSandbox Flaws
vulnerability CVE-2026-25089
general_metric 9.1 second flaw
infrastructure 9.1
organisation FortiSandbox
‎Jun 16, 2026
Threat actors exploited known vulnerabilities in Fortinet's FortiSandbox software to target victims.
‎2026/06/16
Fortinet's FortiSandbox products have been exploited in attacks due to vulnerabilities including CVE-2026-39813 and CVE-2026-39808, which are OS command injection flaws that allow unauthenticated attackers to execute unauthorized code or commands via crafted HTTP requests.
organisation Fortinet FortiSandbox
organisation CVE-2026
organisation CVE-2026-39813
organisation FortiSandbox
organisation Cybersecurity
organisation Fortinet
organisation SQL
organisation the FortiClient Enterprise Management
organisation EMS
organisation Defused
organisation BleepingComputer
organisation EDR
organisation FortiClient EMS
organisation SecurityAffairs
infrastructure 5.0.0
infrastructure 5.0.5
infrastructure 5.0.6
organisation FortiProxy
organisation FortiPortal
organisation FortiOS
Tactical Metrics
Metrics
infrastructure
‎9.1
Software Version
Metrics
infrastructure
‎5.0.0
Software Version
Metrics
infrastructure
‎5.0.5
Software Version
Metrics
infrastructure
‎5.0.6
Software Version
Intelligence Sources
Security Affairs 2026-06-11
BleepingComputer 2026-06-16