• News/
  • bleepingcomputer-20260616091951

Critical Fortinet FortiSandbox flaws now exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Jun 16, 2026
·
Updated

Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused. Fortinet released security updates for these three critical-severity security flaws (tracked as CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089) on April 14. These flaws allow unauthenticated threat actors to escalate privileges and execute unauthorized code remotely through low-complexity command injection attacks that require no user interaction. To resolve these issues and block incoming attacks, admins must upgrade affected deployments to the latest released versions. "We are observing exploitation of multiple Fortinet FortiSandbox vulnerabilities during the past 24 hours, including: CVE-2026-39813 (no previous recorded exploitation), CVE-2026-39808, CVE-2026-25089 (vibecoded, likely faulty exploit)," Defused warned on Monday. "Per our research a working exploit for CVE-2026-25089 has not yet been publicly disclosed." In April, Fortinet also flagged a medium-severity path traversal vulnerability (CVE-2025-61624) as exploited in the wild, a flaw that can let authenticated attackers escalate privileges. However, successful exploitation requires high privileges on the targeted systems, implying that it was very likely chained with another security issue. BleepingComputer reached out to Fortinet to confirm reports of active exploitation, but a response was not immediately available. Fortinet security fl...

Read full article

Affected Software

2 affected components
Fortinet FortiSandbox
Fortinet FortiClient Enterprise Management Server (EMS)
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What critical vulnerabilities are discussed in the article?

The article discusses three critical vulnerabilities in Fortinet's FortiSandbox, identified as CVE-2026-39813, CVE-2026-39808, and others.

2

How are these vulnerabilities being exploited?

Attackers are actively exploiting these vulnerabilities in the FortiSandbox platform to carry out cyber attacks.

3

What security updates has Fortinet released?

Fortinet has released security updates to address the critical vulnerabilities in FortiSandbox.

4

What products are affected by these vulnerabilities?

The vulnerabilities affect Fortinet's FortiSandbox and FortiClient Enterprise Management Server (EMS).

5

When was the exploitation of these vulnerabilities first reported?

The exploitation of these vulnerabilities was first reported on June 17, 2026, as part of the KEV-list.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203