# CISA KEV: Fortinet FortiSandbox OS Command Injection Vulnerabilities Exploited (CVE-2026-39808, CVE-2026-25089)

> CISA added two unauthenticated OS command injection vulnerabilities (CWE-78) in Fortinet FortiSandbox to its Known Exploited Vulnerabilities catalog on July 16, 2026, confirming active exploitation via crafted HTTP requests. CVE-2026-39808 (FG-IR-26-100) hits the FortiSandbox 4.4 API's tracer-behavior job-detail endpoint; CVE-2026-25089 (FG-IR-26-141) hits the FortiSandbox 5.0/Cloud/PaaS web UI's VNC-initialization JSON handler. Both were exploited alongside a related unauthenticated path-traversal auth-bypass flaw, CVE-2026-39813 (FG-IR-26-112), in a June 14-16, 2026 attack wave targeting internet-exposed appliances.

- **Published:** 2026-07-17T00:00:00Z
- **Last reviewed:** 2026-07-18T12:33:21.245Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1432
- **ID:** TL-2026-1432
- **Severity:** CRITICAL (CVSS 9.1)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-39808, CVE-2026-25089, CVE-2026-39813

## Description

Fortinet FortiSandbox is a malware-detonation appliance used by enterprises and MSSPs to render trust verdicts on files traversing perimeter and email security controls. On 2026-04-14 Fortinet published PSIRT advisories FG-IR-26-100 (CVE-2026-39808) and FG-IR-26-112 (CVE-2026-39813) for FortiSandbox 4.4.0-4.4.8 and 4.4.0-4.4.8/5.0.0-5.0.5 respectively, and on 2026-06-09 published FG-IR-26-141 (CVE-2026-25089) covering FortiSandbox 5.0.0-5.0.5, FortiSandbox Cloud 5.0.4-5.0.5, and FortiSandbox PaaS 5.0.4-5.0.5.

CVE-2026-39808 is an OS command injection (CWE-78) in the FortiSandbox API: the `jid` GET parameter of the `/fortisandbox/job-detail/tracer-behavior` endpoint is concatenated unsanitized into a shell invocation, so pipe characters (`|`) let an unauthenticated, network-adjacent attacker chain arbitrary commands that execute with root privileges. A public proof-of-concept (samu-delucas/CVE-2026-39808 on GitHub, credited to Samuel de Lucas Maroto of KPMG Spain) demonstrates a single unauthenticated GET request — `jid=|(id > /web/ng/out.txt)|` — that writes command output directly into the web root for retrieval, giving a trivially reliable, no-interaction RCE primitive.

CVE-2026-25089 is the same root-cause class (CWE-78) in the FortiSandbox web UI's 'start VNC' feature, which parses attacker-controlled JSON during VNC session initialization without sanitizing shell metacharacters, again yielding unauthenticated remote command execution. Fortinet's PSIRT rates both FG-IR-26-100 and FG-IR-26-141 CVSS v3.1 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), though NVD's CNA record for CVE-2026-39808 lists 9.8 — both scorings agree on network-vector, no-privileges, no-interaction, full C/I/A impact.

A third, closely related flaw, CVE-2026-39813 (FG-IR-26-112, CVSS 9.1/9.8, CWE-22 path traversal in the FortiSandbox JRPC API), allows an unauthenticated `../filedir` traversal that bypasses authentication and was exploited in the same campaign window to stage privilege escalation ahead of command injection.

Cloud Security Alliance's FortiSandbox Triple-CVE research note documents an attack chain observed 2026-06-14 through 2026-06-16 combining all three flaws: unauthenticated initial access via CVE-2026-39813 path traversal to bypass auth, command execution via CVE-2026-39808 or CVE-2026-25089, and root-level post-exploitation used to manipulate FortiSandbox malware-analysis verdicts — letting malicious files pass undetected through downstream security controls — plus potential lateral pivoting to connected FortiGate firewalls and FortiMail gateways over Security Fabric channels. Qualys ThreatPROTECT and The Hacker News independently confirmed active exploitation of all three CVEs by mid-to-late June 2026; The Hacker News additionally reported that the CVE-2026-25089 exploit code observed in the wild bore signs of AI-assisted development, though functioning exploitation remained imperfect ("faulty") at time of reporting. CISA added CVE-2026-39808 and CVE-2026-25089 to its KEV catalog on 2026-07-16 with a 2026-07-19 remediation deadline for FCEB agencies under BOD 26-04; no attacker infrastructure (IPs, domains, hashes) has been publicly disclosed by any source reviewed. cybersecuritynews.com additionally notes post-exploitation objectives consistent with the observed TTPs: web shell deployment, credential harvesting, lateral movement, and disabling of security controls.

## MITRE ATT&CK

- T1588.005 Exploits
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1059.004 Unix Shell
- T1505.003 Web Shell
- T1068 Exploitation for Privilege Escalation
- T1548 Abuse Elevation Control Mechanism
- T1685 Disable or Modify Tools
- T1070 Indicator Removal
- T1003 OS Credential Dumping
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1210 Exploitation of Remote Services
- T1005 Data from Local System
- T1102 Web Service
- T1565.001 Stored Data Manipulation

## Sources

- [CISA Warns of Fortinet FortiSandbox OS Injection Vulnerabilities Exploited in Attacks](https://cybersecuritynews.com/fortisandbox-vulnerabilities-exploited/)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [FG-IR-26-100: FortiSandbox OS Command Injection](https://fortiguard.fortinet.com/psirt/FG-IR-26-100)
- [FG-IR-26-141: FortiSandbox OS Command Injection](https://fortiguard.fortinet.com/psirt/FG-IR-26-141)
- [FG-IR-26-112: FortiSandbox Path Traversal](https://fortiguard.fortinet.com/psirt/FG-IR-26-112)
- [CVE-2026-39808 Detail - NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-39808)
- [CVE-2026-25089 Detail - NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-25089)
- [CVE-2026-39813 Detail - NVD](https://nvd.nist.gov/vuln/detail/cve-2026-39813)
- [samu-delucas/CVE-2026-39808 PoC for Unauthenticated RCE in FortiSandbox](https://github.com/samu-delucas/CVE-2026-39808)
- [Fortinet FortiSandbox Vulnerability Exploited by Attackers (CVE-2026-39808, CVE-2026-25089, & CVE-2026-39813)](https://threatprotect.qualys.com/2026/06/17/fortinet-fortisandbox-vulnerability-exploited-by-attackers-cve-2026-39808-cve-2026-25089-cve-2026-39813/)
- [Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week](https://thehackernews.com/2026/06/attackers-exploit-three-fortinet.html)
- [CSA Research Note: FortiSandbox Triple-CVE Exploitation](https://labs.cloudsecurityalliance.org/research/csa-research-note-fortisandbox-triple-cve-exploitation-20260/)
- [Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808)](https://www.helpnetsecurity.com/2026/04/16/fortinet-fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808/)
- [Attackers are exploiting FortiSandbox vulnerabilities](https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1432
