# CISA Orders Federal Agencies to Patch Exploited Fortinet FortiSandbox Command Injection Flaws (CVE-2026-39808, CVE-2026-25089, CVE-2026-39813)

> CISA added three critical Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities catalog on July 16, 2026 after threat-intel firm Defused confirmed in-the-wild exploitation starting June 16, 2026. The flaws — two unauthenticated OS command injection bugs and one path-traversal authentication bypass — can be chained for unauthenticated, low-complexity root-level remote code execution on the appliance that provides malware verdicts to connected FortiGate, FortiMail, and other Security Fabric components. Federal civilian agencies must patch under Binding Operational Directive 26-04 by Sunday, July 19, 2026.

- **Published:** 2026-07-17T00:00:00Z
- **Last reviewed:** 2026-07-17T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1433
- **ID:** TL-2026-1433
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-39808, CVE-2026-25089, CVE-2026-39813

## Description

Fortinet FortiSandbox — a sandboxing appliance that detonates suspicious files/URLs and returns malware verdicts consumed by FortiGate firewalls, FortiMail secure email gateways, and other Fortinet Security Fabric components — is affected by three critical vulnerabilities that adversaries have chained into a full unauthenticated remote-code-execution kill chain.

CVE-2026-39808 (FG-IR-26-100, CVSS 9.1, disclosed 2026-04-14) is an OS command injection [CWE-78] in the '/fortisandbox/job-detail/tracer-behavior' endpoint of the FortiSandbox Web UI. The 'jid' GET parameter is passed unsanitized into a system-level shell command; an attacker injects a pipe ('|') to terminate the intended command and append arbitrary OS commands, which then execute with root privileges. A public PoC (disclosed by researcher Samuel de Lucas of KPMG Spain, and independently reproduced by multiple GitHub researchers) demonstrates the primitive with: curl -s -k --get "http://$HOST/fortisandbox/job-detail/tracer-behavior" --data-urlencode "jid=|(id > /web/ng/out.txt)|". Affects FortiSandbox 4.4.0 through 4.4.8; fixed in 4.4.9+.

CVE-2026-39813 (FG-IR-26-112, CVSS 9.1/9.8 depending on source, disclosed 2026-04-14) is a path traversal [CWE-24, '../filedir'] in the FortiSandbox JRPC API that allows an unauthenticated, remote attacker to send specially crafted HTTP requests to bypass authentication controls entirely, then chain into privilege escalation. Discovered by Adham El Karn of Fortinet's own Product Security team. Affects FortiSandbox 4.4.0 through 4.4.8 and 5.0.0 through 5.0.5. EPSS scored at 16.7% (97th percentile) at disclosure.

CVE-2026-25089 (FG-IR-26-141, CVSS 9.8, disclosed 2026-06-09) is a second-order OS command injection [CWE-78] triggered via JSON input in the FortiSandbox Web UI 'start VNC' feature, again allowing an unauthenticated attacker to execute unauthorized commands via crafted HTTP requests. Affects FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 (all versions), FortiSandbox Cloud 5.0.4 through 5.0.5, and FortiSandbox PaaS 5.0.4 through 5.0.5; fixed in 4.4.9+ / 5.0.6+.

Threat-intelligence firm Defused first publicly reported active exploitation on June 16, 2026, stating it had observed "exploitation of multiple Fortinet FortiSandbox vulnerabilities during the past 24 hours," and noted that at least one in-the-wild exploit variant appeared 'vibecoded' (AI-generated) and likely faulty — suggesting opportunistic, low-skill actors rushed to weaponize the public PoC alongside more capable operators. Analysts assess the CVE-2026-39813 authentication bypass is being chained with the CVE-2026-39808 or CVE-2026-25089 command injection primitives to achieve unauthenticated, root-level RCE on internet-exposed FortiSandbox management interfaces without any user interaction.

Because FortiSandbox issues the malware verdicts that downstream FortiGate and FortiMail devices trust, a compromised appliance gives an attacker persistent access to manipulate analysis results — effectively blinding connected firewalls and email gateways to malicious files and URLs — and a foothold to abuse Security Fabric trust relationships for reconnaissance or C2 traffic that masquerades as internal security-tooling communication. Targeting reporting to date highlights internet-exposed FortiSandbox management interfaces broadly, with specific commentary on financial-sector exposure (e.g., SAMA-regulated Saudi banking institutions required by the SAMA Cyber Security Framework to run advanced malware-protection appliances such as FortiSandbox).

CISA added all three CVEs to the Known Exploited Vulnerabilities (KEV) catalog on 2026-07-16 and, via Binding Operational Directive (BOD) 26-04, ordered FCEB agencies to apply vendor mitigations or discontinue use of the product by 2026-07-19. No ransomware use has been confirmed as of the KEV entry. Vendor guidance is to upgrade FortiSandbox to 4.4.9+ or 5.0.6+ (Cloud/PaaS to 5.0.6+) and to restrict FortiSandbox API/management-interface access to trusted networks only.

## MITRE ATT&CK

- T1595 Active Scanning
- T1588 Obtain Capabilities
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1068 Exploitation for Privilege Escalation
- T1685 Disable or Modify Tools
- T1070 Indicator Removal
- T1199 Trusted Relationship
- T1212 Exploitation for Credential Access
- T1082 System Information Discovery
- T1046 Network Service Discovery
- T1210 Exploitation of Remote Services
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1565 Data Manipulation
- T1491 Defacement

## Sources

- [CISA warns feds to patch exploited Fortinet FortiSandbox flaws by Sunday](https://www.bleepingcomputer.com/news/security/cisa-warns-feds-to-patch-exploited-fortinet-fortisandbox-flaws-by-sunday/)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)
- [FG-IR-26-100: OS Command Injection through API endpoint](https://fortiguard.fortinet.com/psirt/FG-IR-26-100)
- [FG-IR-26-112: FortiSandbox JRPC API Path Traversal](https://fortiguard.fortinet.com/psirt/FG-IR-26-112)
- [FG-IR-26-141: Second-Order OS Command Injection via JSON Input](https://fortiguard.fortinet.com/psirt/FG-IR-26-141)
- [CVE-2026-39808 Detail - NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-39808)
- [CVE-2026-39813 Detail - NVD](https://nvd.nist.gov/vuln/detail/cve-2026-39813)
- [Fortinet FortiSandbox Vulnerability Exploited by Attackers (CVE-2026-39808, CVE-2026-25089, & CVE-2026-39813)](https://threatprotect.qualys.com/2026/06/17/fortinet-fortisandbox-vulnerability-exploited-by-attackers-cve-2026-39808-cve-2026-25089-cve-2026-39813/)
- [Attackers are exploiting FortiSandbox vulnerabilities](https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/)
- [Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808)](https://www.helpnetsecurity.com/2026/04/16/fortinet-fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808/)
- [FortiSandbox Triple-CVE: Security Appliances as Network Entry Points](https://labs.cloudsecurityalliance.org/research/csa-research-note-fortisandbox-triple-cve-exploitation-20260/)
- [FortiSandbox CVE-2026-39808 Unauthenticated RCE — Saudi Financial Sector](https://fyntralink.com/en/blog/fortisandbox-cve-2026-39808-cve-2026-39813-unauthenticated-rce-saudi-financial-sector-2026/)
- [Second-Order OS Command Injection via JSON Input (mirror)](https://www.fortiguard.com/psirt/FG-IR-26-141)
- [GHSA-5f64-p6cf-vvqg: Path traversal '../filedir' in Fortinet FortiSandbox](https://github.com/advisories/GHSA-5f64-p6cf-vvqg)
- [GitHub PoC: samu-delucas/CVE-2026-39808](https://github.com/samu-delucas/CVE-2026-39808)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1433
