ZeroHour

CVE-2026-39808

KEV PoC moderate

Unauthenticated OS Command Injection in Fortinet FortiSandbox 4.4

CISA: Fortinet FortiSandbox OS Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
93%p100
Published
()
KEV added
AI analysis

CVE-2026-39808 is an OS command injection flaw (CWE-78) in Fortinet FortiSandbox versions 4.4.0 through 4.4.8, caused by improper neutralization of special elements passed to OS commands. The vulnerability is network-reachable, requires no privileges or user interaction (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N), though CISA's description does not specify the exact entry point that a remote unauthenticated attacker abuses to trigger it. Successful exploitation lets the attacker execute unauthorized code or commands on the appliance, with high impact to confidentiality, integrity, and availability. Any organization running FortiSandbox 4.4.0-4.4.8 is affected; these sandboxing appliances are typically deployed as add-ons to enterprise FortiGate security estates. The flaw was added to CISA's KEV on 2026-07-16, and press coverage describes critical FortiSandbox bugs coming under active attack, so in-the-wild exploitation should be assumed.

What to do: Upgrade all FortiSandbox appliances out of the affected 4.4.0-4.4.8 range to a fixed release per Fortinet's advisory, prioritizing internet-exposed units and complying with the CISA KEV required action (added 2026-07-16) and BOD 26-04 guidance. Until patched, restrict network access to the appliance's management and analysis interfaces and triage for signs of command execution such as unexpected processes or outbound connections. Confirm the specific fixed 4.4.x build in Fortinet's PSIRT advisory before scheduling upgrades.

Affected
Fortinet FortiSandbox4.4.0 through 4.4.8
Estimated exposure
moderate≈1,000-10,000 deployed FortiSandbox appliances (est.), of which a low thousands are likely internet-exposed — FortiSandbox is a dedicated sandboxing appliance sold as an enterprise add-on rather than a mass-market product, so deployment is far smaller than Fortinet's firewall base; public scan counts of internet-exposed FortiSandbox units…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via

CISA Known Exploited Vulnerability
Affected
Fortinet FortiSandbox
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Due date
Ransomware use
Unknown
Vendors
fortinet
Products
fortisandbox
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news