Threat reportVulnerabilityTL-2026-1433
CISA Orders Federal Agencies to Patch Exploited Fortinet FortiSandbox Command Injection Flaws (CVE-2026-39808, CVE-2026-25089, CVE-2026-39813)
CISA Orders Federal Agencies to Patch Exploited Fortinet (TL-2026-1433) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-17. It has no confirmed attribution, affects Fortinet FortiSandbox, references 3 CVEs (CVE-2026-39808, CVE-2026-25089, CVE-2026-39813), maps to 17 MITRE ATT&CK techniques (T1005, T1046, T1059), and is covered by 9 detection rules and 15 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-1433
- Threat ID
- TL-2026-1433
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, criticalinfrastructure, technology, enterprisesecurityoperations
- Target regions
- North America, Middle East, Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in CISA Orders Federal Agencies to Patch Exploited Fortinet
Malware and tooling: 0xBlackash/CVE-2026-39808 PoC exploit, error-inside/CVE-2026-39808 PoC exploit, samu-delucas/CVE-2026-39808 PoC exploit
How CISA Orders Federal Agencies to Patch Exploited Fortinet works
CISA added three critical Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities catalog on July 16, 2026 after threat-intel firm Defused confirmed in-the-wild exploitation starting June 16, 2026. The flaws — two unauthenticated OS command injection bugs and one path-traversal authentication bypass — can be chained for unauthenticated, low-complexity root-level remote code execution on the appliance that provides malware verdicts to connected FortiGate, FortiMail, and other Security Fabric components. Federal civilian agencies must patch under Binding Operational Directive 26-04 by Sunday, July 19, 2026.
Fortinet FortiSandbox — a sandboxing appliance that detonates suspicious files/URLs and returns malware verdicts consumed by FortiGate firewalls, FortiMail secure email gateways, and other Fortinet Security Fabric components — is affected by three critical vulnerabilities that adversaries have chained into a full unauthenticated remote-code-execution kill chain.
CVE-2026-39808 (FG-IR-26-100, CVSS 9.1, disclosed 2026-04-14) is an OS command injection [CWE-78] in the '/fortisandbox/job-detail/tracer-behavior' endpoint of the FortiSandbox Web UI. The 'jid' GET parameter is passed unsanitized into a system-level shell command; an attacker injects a pipe ('|') to terminate the intended command and append arbitrary OS commands, which then execute with root privileges. A public PoC (disclosed by researcher Samuel de Lucas of KPMG Spain, and independently reproduced by multiple GitHub researchers) demonstrates the primitive with: curl -s -k --get "http://$HOST/fortisandbox/job-detail/tracer-behavior" --data-urlencode "jid=|(id > /web/ng/out.txt)|". Affects FortiSandbox 4.4.0 through 4.4.8; fixed in 4.4.9+.
CVE-2026-39813 (FG-IR-26-112, CVSS 9.1/9.8 depending on source, disclosed 2026-04-14) is a path traversal [CWE-24, '../filedir'] in the FortiSandbox JRPC API that allows an unauthenticated, remote attacker to send specially crafted HTTP requests to bypass authentication controls entirely, then chain into privilege escalation. Discovered by Adham El Karn of Fortinet's own Product Security team. Affects FortiSandbox 4.4.0 through 4.4.8 and 5.0.0 through 5.0.5. EPSS scored at 16.7% (97th percentile) at disclosure.
CVE-2026-25089 (FG-IR-26-141, CVSS 9.8, disclosed 2026-06-09) is a second-order OS command injection [CWE-78] triggered via JSON input in the FortiSandbox Web UI 'start VNC' feature, again allowing an unauthenticated attacker to execute unauthorized commands via crafted HTTP requests. Affects FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 (all versions), FortiSandbox Cloud 5.0.4 through 5.0.5, and FortiSandbox PaaS 5.0.4 through 5.0.5; fixed in 4.4.9+ / 5.0.6+.
Threat-intelligence firm Defused first publicly reported active exploitation on June 16, 2026, stating it had observed "exploitation of multiple Fortinet FortiSandbox vulnerabilities during the past 24 hours," and noted that at least one in-the-wild exploit variant appeared 'vibecoded' (AI-generated) and likely faulty — suggesting opportunistic, low-skill actors rushed to weaponize the public PoC alongside more capable operators. Analysts assess the CVE-2026-39813 authentication bypass is being chained with the CVE-2026-39808 or CVE-2026-25089 command injection primitives to achieve unauthenticated, root-level RCE on internet-exposed FortiSandbox management interfaces without any user interaction.
Because FortiSandbox issues the malware verdicts that downstream FortiGate and FortiMail devices trust, a compromised appliance gives an attacker persistent access to manipulate analysis results — effectively blinding connected firewalls and email gateways to malicious files and URLs — and a foothold to abuse Security Fabric trust relationships for reconnaissance or C2 traffic that masquerades as internal security-tooling communication. Targeting reporting to date highlights internet-exposed FortiSandbox management interfaces broadly, with specific commentary on financial-sector exposure (e.g., SAMA-regulated Saudi banking institutions required by the SAMA Cyber Security Framework to run advanced malware-protection appliances such as FortiSandbox).
CISA added all three CVEs to the Known Exploited Vulnerabilities (KEV) catalog on 2026-07-16 and, via Binding Operational Directive (BOD) 26-04, ordered FCEB agencies to apply vendor mitigations or discontinue use of the product by 2026-07-19. No ransomware use has been confirmed as of the KEV entry. Vendor guidance is to upgrade FortiSandbox to 4.4.9+ or 5.0.6+ (Cloud/PaaS to 5.0.6+) and to restrict FortiSandbox API/management-interface access to trusted networks only.
MITRE ATT&CK techniques used in TL-2026-1433
Collection
Discovery
T1046 Network Service Discovery; T1082 System Information Discovery
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Defense Evasion
Command and Control
T1071 Application Layer Protocol
Initial Access
T1190 Exploit Public-Facing Application
initial-access
Lateral Movement
T1210 Exploitation of Remote Services
Credential Access
T1212 Exploitation for Credential Access
Impact
T1491 Defacement; T1565 Data Manipulation
Resource Development
Reconnaissance
defense-impairment
Affected products and versions in CISA Orders Federal Agencies to Patch Exploited Fortinet
Remediation for CISA Orders Federal Agencies to Patch Exploited Fortinet
Patches
- FortiSandbox 4.4.9 (fixes CVE-2026-39808, CVE-2026-39813, CVE-2026-25089)
- FortiSandbox 5.0.6 (fixes CVE-2026-39813, CVE-2026-25089)
- FortiSandbox Cloud 5.0.6 (fixes CVE-2026-25089)
- FortiSandbox PaaS 5.0.6 (fixes CVE-2026-25089)
Immediate actions
- Upgrade FortiSandbox to 4.4.9 or later
- Upgrade FortiSandbox to 5.0.6 or later
- Upgrade FortiSandbox Cloud to 5.0.6 or later
- Upgrade FortiSandbox PaaS to 5.0.6 or later
- Restrict FortiSandbox web UI, API, and JRPC interface access to trusted management networks only; remove from direct internet exposure
- Federal agencies: comply with BOD 26-04 patch/mitigate-or-discontinue deadline of 2026-07-19
- Hunt for indicators of compromise on the '/fortisandbox/job-detail/tracer-behavior' endpoint and unexpected JRPC API authentication events
- Review FortiSandbox-issued malware verdicts for tampering if compromise is suspected, given downstream trust by FortiGate/FortiMail
Workarounds
- If patching is not immediately possible, discontinue use of the affected FortiSandbox instance per BOD 26-04 guidance
- Restrict access to the FortiSandbox management/API interfaces to a trusted, segmented management network
Longer-term hardening
- Place all Fortinet Security Fabric management interfaces behind VPN/jump-host access, never expose directly to the internet
- Implement network segmentation isolating security appliance management planes from general enterprise networks
- Deploy WAF/IPS signatures for shell-metacharacter injection and path-traversal patterns against FortiSandbox endpoints
- Establish a rapid-patch SLA for CISA KEV-listed vulnerabilities affecting perimeter/security infrastructure
- Monitor Security Fabric device-to-device trust traffic for anomalous or unexpected verdict-manipulation patterns
CVEs associated with CISA Orders Federal Agencies to Patch Exploited Fortinet
CVE-2026-39808, CVE-2026-25089, CVE-2026-39813
Weaknesses (CWE) in CISA Orders Federal Agencies to Patch Exploited Fortinet
Timeline of CISA Orders Federal Agencies to Patch Exploited Fortinet
- Fortinet publishes PSIRT advisories FG-IR-26-100 (CVE-2026-39808) and FG-IR-26-112 (CVE-2026-39813); patches available in FortiSandbox 4.4.9.
- Researcher Samuel de Lucas (KPMG Spain) publishes technical writeup and PoC exploit code for CVE-2026-39808 on GitHub, demonstrating command injection via the 'jid' parameter of the tracer-behavior endpoint.
- Multiple independent researchers (error-inside, 0xBlackash) publish reproduced PoC repositories for CVE-2026-39808, broadening public exploit availability.
- Fortinet publishes PSIRT advisory FG-IR-26-141 for CVE-2026-25089, a second-order OS command injection reachable via the FortiSandbox web UI 'start VNC' JSON input.
- Analysts assess opportunistic in-the-wild exploitation of the FortiSandbox vulnerabilities begins over this weekend, ahead of public disclosure of active attacks.
- Threat-intelligence firm Defused publicly reports observing exploitation of multiple FortiSandbox vulnerabilities in the prior 24 hours, noting one in-the-wild exploit variant appears AI-generated ('vibecoded') and likely faulty.
- Qualys ThreatPROTECT and Help Net Security publish independent analyses confirming active exploitation across all three CVEs (CVE-2026-39808, CVE-2026-25089, CVE-2026-39813).
- Cloud Security Alliance research labs publish a technical note describing the chained exploitation sequence: CVE-2026-39813 authentication bypass combined with CVE-2026-39808/CVE-2026-25089 command injection for root-level RCE, and warning of Security Fabric trust-relationship abuse.
- CISA's KEV catalog records CVE-2026-25089 and related entries as dated into the catalog (per catalog dateAdded metadata).
- CISA issues remediation requirement under Binding Operational Directive 26-04, mandating FCEB agencies apply vendor mitigations or discontinue use of affected FortiSandbox instances.
- CISA formally adds CVE-2026-39808 and CVE-2026-25089 (and associated CVE-2026-39813 chain) to the Known Exploited Vulnerabilities catalog, citing confirmed active exploitation.
- BleepingComputer reports on the CISA KEV addition and the July 19 federal patch deadline, summarizing the active-exploitation timeline and Defused's original disclosure.
- BOD 26-04 compliance deadline: FCEB agencies must have patched or mitigated/discontinued affected FortiSandbox deployments.
Sources cited for CISA Orders Federal Agencies to Patch Exploited Fortinet
- CISA warns feds to patch exploited Fortinet FortiSandbox flaws by Sunday
- CISA Known Exploited Vulnerabilities Catalog
- FG-IR-26-100: OS Command Injection through API endpoint
- FG-IR-26-112: FortiSandbox JRPC API Path Traversal
- FG-IR-26-141: Second-Order OS Command Injection via JSON Input
- CVE-2026-39808 Detail - NVD
- CVE-2026-39813 Detail - NVD
- Fortinet FortiSandbox Vulnerability Exploited by Attackers (CVE-2026-39808, CVE-2026-25089, & CVE-2026-39813)
- Attackers are exploiting FortiSandbox vulnerabilities
- Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808)
- FortiSandbox Triple-CVE: Security Appliances as Network Entry Points
- FortiSandbox CVE-2026-39808 Unauthenticated RCE — Saudi Financial Sector
- Second-Order OS Command Injection via JSON Input (mirror)
- GHSA-5f64-p6cf-vvqg: Path traversal '../filedir' in Fortinet FortiSandbox
- GitHub PoC: samu-delucas/CVE-2026-39808
Detection coverage for TL-2026-1433
As of 2026-07-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1433 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.