Threat reportVulnerabilityTL-2026-1432

CISA KEV: Fortinet FortiSandbox OS Command Injection Vulnerabilities Exploited (CVE-2026-39808, CVE-2026-25089)

criticalACTIVE

CISA KEV: Fortinet FortiSandbox OS Command Injection (TL-2026-1432), also tracked as FortiSandbox Triple-CVE Exploitation, is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-07-17 and last reviewed 2026-07-18. It has no confirmed attribution, affects Fortinet FortiSandbox, references 3 CVEs (CVE-2026-39808, CVE-2026-25089, CVE-2026-39813), maps to 16 MITRE ATT&CK techniques (T1003, T1005, T1059), and is covered by 9 detection rules and 28 indicators of compromise.

CVSS
9.1/10Critical
CVEs
3Referenced vulnerabilities
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-1432

Threat ID
TL-2026-1432
Also known as
FortiSandbox Triple-CVE Exploitation
Severity
CRITICAL
CVSS
9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
28
Updates
2026-07-18 · revalidated 1× · latest source

Malware and tooling in CISA KEV: Fortinet FortiSandbox OS Command Injection

Malware and tooling: samu-delucas/CVE-2026-39808 GitHub PoC

How CISA KEV: Fortinet FortiSandbox OS Command Injection works

CISA added two unauthenticated OS command injection vulnerabilities (CWE-78) in Fortinet FortiSandbox to its Known Exploited Vulnerabilities catalog on July 16, 2026, confirming active exploitation via crafted HTTP requests. CVE-2026-39808 (FG-IR-26-100) hits the FortiSandbox 4.4 API's tracer-behavior job-detail endpoint; CVE-2026-25089 (FG-IR-26-141) hits the FortiSandbox 5.0/Cloud/PaaS web UI's VNC-initialization JSON handler. Both were exploited alongside a related unauthenticated path-traversal auth-bypass flaw, CVE-2026-39813 (FG-IR-26-112), in a June 14-16, 2026 attack wave targeting internet-exposed appliances.

Fortinet FortiSandbox is a malware-detonation appliance used by enterprises and MSSPs to render trust verdicts on files traversing perimeter and email security controls. On 2026-04-14 Fortinet published PSIRT advisories FG-IR-26-100 (CVE-2026-39808) and FG-IR-26-112 (CVE-2026-39813) for FortiSandbox 4.4.0-4.4.8 and 4.4.0-4.4.8/5.0.0-5.0.5 respectively, and on 2026-06-09 published FG-IR-26-141 (CVE-2026-25089) covering FortiSandbox 5.0.0-5.0.5, FortiSandbox Cloud 5.0.4-5.0.5, and FortiSandbox PaaS 5.0.4-5.0.5.

CVE-2026-39808 is an OS command injection (CWE-78) in the FortiSandbox API: the `jid` GET parameter of the `/fortisandbox/job-detail/tracer-behavior` endpoint is concatenated unsanitized into a shell invocation, so pipe characters (`|`) let an unauthenticated, network-adjacent attacker chain arbitrary commands that execute with root privileges. A public proof-of-concept (samu-delucas/CVE-2026-39808 on GitHub, credited to Samuel de Lucas Maroto of KPMG Spain) demonstrates a single unauthenticated GET request — `jid=|(id > /web/ng/out.txt)|` — that writes command output directly into the web root for retrieval, giving a trivially reliable, no-interaction RCE primitive.

CVE-2026-25089 is the same root-cause class (CWE-78) in the FortiSandbox web UI's 'start VNC' feature, which parses attacker-controlled JSON during VNC session initialization without sanitizing shell metacharacters, again yielding unauthenticated remote command execution. Fortinet's PSIRT rates both FG-IR-26-100 and FG-IR-26-141 CVSS v3.1 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), though NVD's CNA record for CVE-2026-39808 lists 9.8 — both scorings agree on network-vector, no-privileges, no-interaction, full C/I/A impact.

A third, closely related flaw, CVE-2026-39813 (FG-IR-26-112, CVSS 9.1/9.8, CWE-22 path traversal in the FortiSandbox JRPC API), allows an unauthenticated `../filedir` traversal that bypasses authentication and was exploited in the same campaign window to stage privilege escalation ahead of command injection.

Cloud Security Alliance's FortiSandbox Triple-CVE research note documents an attack chain observed 2026-06-14 through 2026-06-16 combining all three flaws: unauthenticated initial access via CVE-2026-39813 path traversal to bypass auth, command execution via CVE-2026-39808 or CVE-2026-25089, and root-level post-exploitation used to manipulate FortiSandbox malware-analysis verdicts — letting malicious files pass undetected through downstream security controls — plus potential lateral pivoting to connected FortiGate firewalls and FortiMail gateways over Security Fabric channels. Qualys ThreatPROTECT and The Hacker News independently confirmed active exploitation of all three CVEs by mid-to-late June 2026; The Hacker News additionally reported that the CVE-2026-25089 exploit code observed in the wild bore signs of AI-assisted development, though functioning exploitation remained imperfect ("faulty") at time of reporting. CISA added CVE-2026-39808 and CVE-2026-25089 to its KEV catalog on 2026-07-16 with a 2026-07-19 remediation deadline for FCEB agencies under BOD 26-04; no attacker infrastructure (IPs, domains, hashes) has been publicly disclosed by any source reviewed. cybersecuritynews.com additionally notes post-exploitation objectives consistent with the observed TTPs: web shell deployment, credential harvesting, lateral movement, and disabling of security controls.

MITRE ATT&CK techniques used in TL-2026-1432

Credential Access

T1003 OS Credential Dumping

Collection

T1005 Data from Local System

Execution

T1059 Command and Scripting Interpreter; T1059.004 Unix Shell

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Defense Evasion

T1070 Indicator Removal

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Command and Control

T1102 Web Service

Initial Access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Persistence

T1505.003 Web Shell

Impact

T1565.001 Stored Data Manipulation

Resource Development

T1588.005 Exploits

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in CISA KEV: Fortinet FortiSandbox OS Command Injection

  • Fortinet — FortiSandbox
    Vulnerable versions: 4.4.0; 4.4.1; 4.4.2; 4.4.3; 4.4.4; 4.4.5; 4.4.6; 4.4.7; 4.4.8
    Fixed in: 4.4.9
  • Fortinet — FortiSandbox
    Vulnerable versions: 5.0.0; 5.0.1; 5.0.2; 5.0.3; 5.0.4; 5.0.5
    Fixed in: 5.0.6
  • Fortinet — FortiSandbox Cloud
    Vulnerable versions: 5.0.4; 5.0.5
    Fixed in: 5.0.6
  • Fortinet — FortiSandbox PaaS
    Vulnerable versions: 5.0.4; 5.0.5
    Fixed in: 5.0.6

Remediation for CISA KEV: Fortinet FortiSandbox OS Command Injection

Patches

  • FortiSandbox 4.4.9 (fixes CVE-2026-39808, CVE-2026-39813)
  • FortiSandbox 5.0.6 / FortiSandbox Cloud 5.0.6 / FortiSandbox PaaS 5.0.6 (fixes CVE-2026-25089, CVE-2026-39813)

Immediate actions

  • Upgrade FortiSandbox 4.4.x to 4.4.9 or later
  • Upgrade FortiSandbox 5.0.x, FortiSandbox Cloud 5.0.x, and FortiSandbox PaaS 5.0.x to 5.0.6 or later
  • Restrict management/API/web UI access to trusted management networks only; remove from direct internet exposure
  • Federal agencies must remediate CVE-2026-39808 and CVE-2026-25089 per CISA BOD 26-04 by 2026-07-19

Workarounds

  • If patching is not immediately possible, disable or firewall off the affected API and 'start VNC' web UI feature
  • Discontinue product use per CISA guidance if vendor mitigations cannot be applied

Longer-term hardening

  • Deploy network segmentation isolating sandbox appliances from production/detection-control trust paths
  • Monitor appliance logs for anomalous shell-spawning by web server processes and unexpected outbound connections
  • Independently re-verify malware-analysis verdicts produced by any FortiSandbox instance exposed during the 2026-06-14 to 2026-06-16 exploitation window
  • Review Security Fabric-connected FortiGate/FortiMail devices for lateral pivot indicators if paired FortiSandbox was exposed

CVEs associated with CISA KEV: Fortinet FortiSandbox OS Command Injection

CVE-2026-39808, CVE-2026-25089, CVE-2026-39813

Weaknesses (CWE) in CISA KEV: Fortinet FortiSandbox OS Command Injection

CWE-78, CWE-22

Timeline of CISA KEV: Fortinet FortiSandbox OS Command Injection

  • Fortinet publishes FG-IR-26-100 (CVE-2026-39808) and FG-IR-26-112 (CVE-2026-39813), fixed in FortiSandbox 4.4.9
  • Help Net Security reports on the two April FortiSandbox advisories
  • Fortinet publishes FG-IR-26-141 (CVE-2026-25089), fixed in FortiSandbox 5.0.6
  • Cloud Security Alliance observes active exploitation begin, chaining CVE-2026-39813 path traversal with CVE-2026-39808/CVE-2026-25089 command injection against internet-exposed FortiSandbox appliances
  • Help Net Security and Cloud Security Alliance publish independent confirmation of active exploitation across all three CVEs
  • CrowdSec releases a detection rule for CVE-2026-39808 and observes the first in-the-wild exploitation attempts the same day; its exploit tracker later logs 49 unique malicious IP addresses scanning for and probing vulnerable FortiSandbox appliances.
  • Qualys ThreatPROTECT and The Hacker News report active in-the-wild exploitation; note CVE-2026-25089 exploit code shows signs of AI-assisted development
  • CISA adds CVE-2026-39808 and CVE-2026-25089 to the Known Exploited Vulnerabilities catalog, confirming active exploitation
  • CyberSecurityNews publishes coverage of the CISA KEV addition; ingested as TL-2026-1432
  • CISA BOD 26-04 remediation deadline for FCEB agencies to patch or discontinue use of affected FortiSandbox instances

Update history for TL-2026-1432

Sources cited for CISA KEV: Fortinet FortiSandbox OS Command Injection

Detection coverage for TL-2026-1432

As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1432 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats