ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

CISA Mandates Urgent Patch for Actively Exploited Fortinet Flaws

criticalVulnerability exploited in the wildimportance 60CVE-2026-39808CVE-2026-25089

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-25089
Unauthenticated OS Command Injection RCE in Fortinet FortiSandbox

CVE-2026-25089 is an OS command injection flaw (CWE-78) in Fortinet FortiSandbox caused by improper neutralization of special elements in OS commands, allowing an unauthenticated attacker to execute unauthorized commands by sending specifically crafted HTTP requests to the product. The flaw is network-exploitable with no privileges or user interaction required (CVSS 3.1 score of 9.8), meaning any reachable instance — hardware/VM appliance, FortiSandbox Cloud, or FortiSandbox PaaS — is exposed to system-level command execution. Successful exploitation carries high impact to confidentiality, integrity, and availability on the sandbox itself and can serve as a foothold into the surrounding network. Organizations running FortiSandbox 5.0.0–5.0.5, 4.4.0–4.4.8, or 4.2 (all versions), as well as FortiSandbox Cloud 5.0.4–5.0.5 and FortiSandbox PaaS 5.0.4–5.0.5, are affected. The vulnerability is being actively exploited in the wild: CISA added it to the KEV catalog on 2026-07-16, EPSS assigns a 76.1% probability of exploitation within 30 days (100th percentile), and news coverage describes FortiSandbox bugs under active attack, though no public proof-of-concept is known.

Do: Upgrade FortiSandbox to a release beyond the affected ranges — newer than 5.0.5, 4.4.8, and 4.2 — and update FortiSandbox Cloud and PaaS beyond 5.0.5, following Fortinet's PSIRT advisory for the exact fixed versions (not specified in this data). Until patched, restrict the FortiSandbox management interface from direct internet exposure and review appliance logs for signs of command-injection exploitation. Organizations subject to CISA's KEV requirements must apply vendor mitigations per BOD 26-04 timelines or discontinue cloud use of the product if mitigations are unavailable.

9.876% KEV
  • Fortinet FortiSandbox 5.0.0 through 5.0.5
  • Fortinet FortiSandbox 4.4.0 through 4.4.8
  • Fortinet FortiSandbox 4.2 (all versions)
  • +2 more
largelikely tens of thousands of deployments worldwide (10k–100k systems across appliance, VM, Cloud, and PaaS), with only a subset internet-exposed; exact install…
CVE-2026-39808
Unauthenticated OS Command Injection in Fortinet FortiSandbox 4.4

CVE-2026-39808 is an OS command injection flaw (CWE-78) in Fortinet FortiSandbox versions 4.4.0 through 4.4.8, caused by improper neutralization of special elements passed to OS commands. The vulnerability is network-reachable, requires no privileges or user interaction (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N), though CISA's description does not specify the exact entry point that a remote unauthenticated attacker abuses to trigger it. Successful exploitation lets the attacker execute unauthorized code or commands on the appliance, with high impact to confidentiality, integrity, and availability. Any organization running FortiSandbox 4.4.0-4.4.8 is affected; these sandboxing appliances are typically deployed as add-ons to enterprise FortiGate security estates. The flaw was added to CISA's KEV on 2026-07-16, and press coverage describes critical FortiSandbox bugs coming under active attack, so in-the-wild exploitation should be assumed.

Do: Upgrade all FortiSandbox appliances out of the affected 4.4.0-4.4.8 range to a fixed release per Fortinet's advisory, prioritizing internet-exposed units and complying with the CISA KEV required action (added 2026-07-16) and BOD 26-04 guidance. Until patched, restrict network access to the appliance's management and analysis interfaces and triage for signs of command execution such as unexpected processes or outbound connections. Confirm the specific fixed 4.4.x build in Fortinet's PSIRT advisory before scheduling upgrades.

9.893% KEV PoC
  • Fortinet FortiSandbox 4.4.0 through 4.4.8
moderate≈1,000-10,000 deployed FortiSandbox appliances (est.), of which a low thousands are likely internet-exposed
Full article282 words · extracted from infosecurity-magazine.com · click to collapse

Two vulnerabilities affecting Fortinet’s malware analysis and detection FortiSandbox have been exploited in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) has warned.

The vulnerabilities, tracked as CVE-2026-39808 and CVE-2026-25089 are both critical, with a severity rating (CVSS) of 9.1 each.

CISA added both to its Known Exploited Vulnerabilities (KEV) catalog on July 16, suggesting evidence of observed exploitation in the wild.

The agency urged rolling out patches across federal government by July 19.

ForitSandbox Exploits Can Lead to Execute Rogue Commands

CVE-2026-39808 was detected by Samuel de Lucas Maroto, a security researcher at KPMG Spain, and disclosed by Fortinet on April 14.

It is an operating system (OS) command injection vulnerability affecting Fortinet’s FortiSandbox versions 4.4.0 to 4.4.8.

When exploited, it allows an attacker to execute unauthorized code or commands via .

Fortinet has released a patch in FortiSandbox version 4.4.9.

The second bug, CVE-2026-25089, was initially identified by Adham El Karn, a security researcher within the Fortinet Product Security team, and  was disclosed by the cybersecurity firm on June 9.

It is an OS command injection vulnerability affecting Fortinet’s FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8 and all 4.2 versions, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5.

When exploited, it allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

Fortinet has released a patch in FortiSandbox versions 4.4.9 and 5.0.6.

CISA required US federal agencies to apply mitigations and patches released by Fortinet.

For cloud-based services, agencies should discontinue using the product if mitigations are unavailable.

CISA has not confirmed whether these vulnerabilities have been used in ransomware campaigns.

Image credits: Piotr Swat / bluestork / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-urgent-patch-fortinet/