Threat reportVulnerabilityTL-2026-1447
CISA Orders Patch of Actively Exploited Critical FortiSandbox OS Command Injection Flaws (CVE-2026-39808, CVE-2026-25089, CVE-2026-39813)
CISA Orders Patch of Actively Exploited Critical (TL-2026-1447) is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-07-17. It has no confirmed attribution, affects Fortinet FortiSandbox, references 3 CVEs (CVE-2026-39808, CVE-2026-25089, CVE-2026-39813), maps to 17 MITRE ATT&CK techniques (T1005, T1041, T1046), and is covered by 9 detection rules and 19 indicators of compromise.
- CVSS
- 9.1/10Critical
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 19Indicators of compromise
Key facts for TL-2026-1447
- Threat ID
- TL-2026-1447
- Severity
- CRITICAL
- CVSS
- 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, critical infrastructure, telecoms
- Target regions
- Global, North America
- Detection rules
- 9
- Indicators of compromise
- 19
How CISA Orders Patch of Actively Exploited Critical works
CISA added two critical unauthenticated OS command injection vulnerabilities in Fortinet FortiSandbox (CVE-2026-39808, CVE-2026-25089, both CVSS 9.1) to its Known Exploited Vulnerabilities catalog on July 16, 2026 after threat intelligence firm Defused confirmed active exploitation, ordering federal civilian agencies under BOD 26-04 to patch by July 19, 2026. A third flaw, CVE-2026-39813 (path traversal / authentication bypass in the JRPC API), is being chained alongside the command injection bugs in observed attacks.
FortiSandbox is Fortinet's malware-analysis and sandboxing appliance that other Fortinet security products (FortiGate, FortiMail, FortiWeb, etc.) rely on for threat verdicts to enforce blocking decisions and trigger automated response. Three vulnerabilities affecting FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS have been chained by attackers in the wild.
CVE-2026-39808 (FG-IR-26-112, disclosed April 14, 2026) is an OS command injection vulnerability (CWE-78) in the FortiSandbox API affecting versions 4.4.0-4.4.8. A publicly available PoC targets the `/fortisandbox/job-detail/tracer-behavior` endpoint, injecting shell metacharacters (pipe operators) into the `jid` (job ID) URL parameter, e.g. decoded payload `|(echo canary > /web/ng/proof.php)|`. Because the parameter is passed unsanitized into a shell command executed by a backend service running as root, a single unauthenticated HTTP GET request achieves remote code execution with full root privileges — no login, no user interaction, low attack complexity.
CVE-2026-39813 (FG-IR-26-112, disclosed April 14, 2026, CVSS 9.1) is a path traversal vulnerability in the FortiSandbox JRPC API's session-validation logic. The `is_valid_session()` function passes a user-supplied `session` value directly into Python's `os.path.join()` without sanitization; supplying a value such as `../../tmp/` causes the check to validate against `/tmp/`, a directory that always exists and whose modification time is continuously refreshed by normal system activity — bypassing authentication entirely. Exploitation grants read-only access to system information: firmware/audit data, system version, hostname, serial number, CPU/RAM/disk utilization, and scan configuration, which attackers use for reconnaissance ahead of further exploitation. Affects FortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5.
CVE-2026-25089 (FG-IR-26-141, disclosed June 9, 2026, discovered internally by Adham El Karn of the Fortinet Product Security team) is a second-order OS command injection vulnerability in the FortiSandbox web GUI's 'start vnc' feature, triggered via crafted JSON input in specially crafted HTTP requests. It affects FortiSandbox 5.0.0-5.0.5, FortiSandbox 4.4.0-4.4.8, FortiSandbox Cloud 5.0.4-5.0.5, and FortiSandbox PaaS 5.0.4-5.0.5. CVSS v3.1 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C) — the E:F (exploit code functional) modifier and RC:C (report confidence confirmed) reflect Fortinet's own acknowledgment of functional public exploitation, though outside researchers describe the observed CVE-2026-25089 exploit attempts as 'vibecoded' (AI-generated, low quality) and largely non-functional.
Threat intelligence firm Defused first reported active in-the-wild abuse of all three CVEs on/around June 16, 2026. Fortinet has not publicly confirmed exploitation and has not released IOCs beyond what independent researchers have derived from PoC and honeypot analysis. CISA added CVE-2026-39808 and CVE-2026-25089 to the KEV catalog on July 16, 2026 with a July 19, 2026 remediation deadline for federal civilian agencies under BOD 26-04. Remediation is to upgrade to FortiSandbox 4.4.9+ or 5.0.6+ (Cloud/PaaS to 5.0.6+) and restrict management/API interface exposure to trusted networks. FortiSandbox is a particularly high-value target because compromise exposes previously-submitted malware samples and can be used to falsify threat verdicts fed to connected FortiGate/FortiMail/FortiWeb enforcement points, plus provides a pivot point into the internal network segments FortiSandbox is deployed to inspect traffic from.
MITRE ATT&CK techniques used in TL-2026-1447
Collection
T1005 Data from Local System; T1119 Automated Collection
Exfiltration
T1041 Exfiltration Over C2 Channel
Discovery
T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Execution
T1059 Command and Scripting Interpreter; T1059.004 Unix Shell
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Initial Access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Defense Evasion
T1211 Exploitation for Stealth
Credential Access
T1212 Exploitation for Credential Access
Persistence
Impact
T1565.001 Stored Data Manipulation
Resource Development
Reconnaissance
Affected products and versions in CISA Orders Patch of Actively Exploited Critical
Remediation for CISA Orders Patch of Actively Exploited Critical
Patches
- Fortinet FG-IR-26-112 (CVE-2026-39808, CVE-2026-39813) — fixed in FortiSandbox 4.4.9 / 5.0.6
- Fortinet FG-IR-26-141 (CVE-2026-25089) — fixed in FortiSandbox 4.4.9 / 5.0.6 / Cloud & PaaS 5.0.6
Immediate actions
- Upgrade FortiSandbox 4.4.x to 4.4.9 or later
- Upgrade FortiSandbox 5.0.x to 5.0.6 or later
- Upgrade FortiSandbox Cloud and FortiSandbox PaaS deployments to 5.0.6 or later
- Restrict access to the FortiSandbox management GUI and API endpoints to trusted/internal networks only
- Federal civilian agencies must remediate per CISA BOD 26-04 by 2026-07-19
Workarounds
- If patching is not immediately possible, disable or firewall external/WAN access to the FortiSandbox GUI and API
- Restrict outbound network access from the FortiSandbox appliance to limit post-exploitation pivoting
Longer-term hardening
- Place FortiSandbox management interfaces behind VPN or bastion access, never expose directly to the internet
- Monitor FortiSandbox logs for anomalous requests to job-detail/tracer-behavior and JRPC session endpoints
- Deploy network segmentation limiting FortiSandbox's ability to pivot to other internal segments if compromised
- Review historical malware sample access logs for unauthorized retrieval following any suspected exploitation window
- Establish a patch-validation cadence for Fortinet security-appliance CVEs given the platform's recurring KEV additions
CVEs associated with CISA Orders Patch of Actively Exploited Critical
CVE-2026-39808, CVE-2026-25089, CVE-2026-39813
Weaknesses (CWE) in CISA Orders Patch of Actively Exploited Critical
Timeline of CISA Orders Patch of Actively Exploited Critical
- Fortinet publishes FG-IR-26-112, disclosing CVE-2026-39808 (OS command injection) and CVE-2026-39813 (path traversal auth bypass) in FortiSandbox, with fixes in 4.4.9 and 5.0.6
- Public PoC exploit for CVE-2026-39808 published on GitHub (error-inside/CVE-2026-39808) targeting the tracer-behavior endpoint's jid parameter
- Fortinet publishes FG-IR-26-141, disclosing CVE-2026-25089, a second-order OS command injection in the FortiSandbox web GUI's start-vnc feature, discovered internally by Adham El Karn
- Help Net Security, The Hacker News, and SecurityWeek publish coverage of the active exploitation of the three FortiSandbox CVEs
- Threat intelligence firm Defused reports active in-the-wild exploitation attempts against all three FortiSandbox CVEs (39808, 25089, 39813); CVE-2026-25089 exploit attempts described as low-quality/'vibecoded'
- CISA and industry outlets (BleepingComputer, Infosecurity Magazine) publish coverage of the KEV addition and patch mandate
- CISA adds CVE-2026-39808 and CVE-2026-25089 to the Known Exploited Vulnerabilities catalog, triggering BOD 26-04 remediation requirements for federal civilian agencies
- The Register reports on attackers targeting the critical FortiSandbox flaws as CISA issues the patch order, source article for this threat record
- CISA BOD 26-04 deadline for federal civilian executive branch agencies to remediate CVE-2026-39808 and CVE-2026-25089
Sources cited for CISA Orders Patch of Actively Exploited Critical
- Attackers target critical FortiSandbox flaws as CISA issues patch order
- CISA warns feds to patch exploited Fortinet FortiSandbox flaws by Sunday
- Attackers are exploiting FortiSandbox vulnerabilities
- Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808)
- Fortinet FortiSandbox Vulnerability Exploited by Attackers (CVE-2026-39808, CVE-2026-25089, & CVE-2026-39813)
- Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
- FG-IR-26-141 - PSIRT | FortiGuard Labs
- CVE-2026-39813 - PSIRT | FortiGuard Labs
- CVE-2026-39813 Deep Dive: Path Traversal Authentication Bypass in FortiSandbox JRPC API
- FortiSandbox Vulnerabilities Expose Systems to Auth Bypass and Command Execution
- GitHub - error-inside/CVE-2026-39808: Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint
- FortiSandbox Root Sandbox Escape - CVE-2026-39808
- CVE-2026-25089: Fortinet FortiSandbox Unauthenticated OS Command Injection — How to Find Exposed Instances on Your Network
- 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs
- CISA Known Exploited Vulnerabilities Catalog
Detection coverage for TL-2026-1447
As of 2026-07-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1447 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.