# CISA Orders Patch of Actively Exploited Critical FortiSandbox OS Command Injection Flaws (CVE-2026-39808, CVE-2026-25089, CVE-2026-39813)

> CISA added two critical unauthenticated OS command injection vulnerabilities in Fortinet FortiSandbox (CVE-2026-39808, CVE-2026-25089, both CVSS 9.1) to its Known Exploited Vulnerabilities catalog on July 16, 2026 after threat intelligence firm Defused confirmed active exploitation, ordering federal civilian agencies under BOD 26-04 to patch by July 19, 2026. A third flaw, CVE-2026-39813 (path traversal / authentication bypass in the JRPC API), is being chained alongside the command injection bugs in observed attacks.

- **Published:** 2026-07-17T00:00:00Z
- **Last reviewed:** 2026-07-17T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1447
- **ID:** TL-2026-1447
- **Severity:** CRITICAL (CVSS 9.1)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-39808, CVE-2026-25089, CVE-2026-39813

## Description

FortiSandbox is Fortinet's malware-analysis and sandboxing appliance that other Fortinet security products (FortiGate, FortiMail, FortiWeb, etc.) rely on for threat verdicts to enforce blocking decisions and trigger automated response. Three vulnerabilities affecting FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS have been chained by attackers in the wild.

CVE-2026-39808 (FG-IR-26-112, disclosed April 14, 2026) is an OS command injection vulnerability (CWE-78) in the FortiSandbox API affecting versions 4.4.0-4.4.8. A publicly available PoC targets the `/fortisandbox/job-detail/tracer-behavior` endpoint, injecting shell metacharacters (pipe operators) into the `jid` (job ID) URL parameter, e.g. decoded payload `|(echo canary > /web/ng/proof.php)|`. Because the parameter is passed unsanitized into a shell command executed by a backend service running as root, a single unauthenticated HTTP GET request achieves remote code execution with full root privileges — no login, no user interaction, low attack complexity.

CVE-2026-39813 (FG-IR-26-112, disclosed April 14, 2026, CVSS 9.1) is a path traversal vulnerability in the FortiSandbox JRPC API's session-validation logic. The `is_valid_session()` function passes a user-supplied `session` value directly into Python's `os.path.join()` without sanitization; supplying a value such as `../../tmp/` causes the check to validate against `/tmp/`, a directory that always exists and whose modification time is continuously refreshed by normal system activity — bypassing authentication entirely. Exploitation grants read-only access to system information: firmware/audit data, system version, hostname, serial number, CPU/RAM/disk utilization, and scan configuration, which attackers use for reconnaissance ahead of further exploitation. Affects FortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5.

CVE-2026-25089 (FG-IR-26-141, disclosed June 9, 2026, discovered internally by Adham El Karn of the Fortinet Product Security team) is a second-order OS command injection vulnerability in the FortiSandbox web GUI's 'start vnc' feature, triggered via crafted JSON input in specially crafted HTTP requests. It affects FortiSandbox 5.0.0-5.0.5, FortiSandbox 4.4.0-4.4.8, FortiSandbox Cloud 5.0.4-5.0.5, and FortiSandbox PaaS 5.0.4-5.0.5. CVSS v3.1 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C) — the E:F (exploit code functional) modifier and RC:C (report confidence confirmed) reflect Fortinet's own acknowledgment of functional public exploitation, though outside researchers describe the observed CVE-2026-25089 exploit attempts as 'vibecoded' (AI-generated, low quality) and largely non-functional.

Threat intelligence firm Defused first reported active in-the-wild abuse of all three CVEs on/around June 16, 2026. Fortinet has not publicly confirmed exploitation and has not released IOCs beyond what independent researchers have derived from PoC and honeypot analysis. CISA added CVE-2026-39808 and CVE-2026-25089 to the KEV catalog on July 16, 2026 with a July 19, 2026 remediation deadline for federal civilian agencies under BOD 26-04. Remediation is to upgrade to FortiSandbox 4.4.9+ or 5.0.6+ (Cloud/PaaS to 5.0.6+) and restrict management/API interface exposure to trusted networks. FortiSandbox is a particularly high-value target because compromise exposes previously-submitted malware samples and can be used to falsify threat verdicts fed to connected FortiGate/FortiMail/FortiWeb enforcement points, plus provides a pivot point into the internal network segments FortiSandbox is deployed to inspect traffic from.

## MITRE ATT&CK

- T1595 Active Scanning
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1059.004 Unix Shell
- T1211 Exploitation for Stealth
- T1212 Exploitation for Credential Access
- T1082 System Information Discovery
- T1046 Network Service Discovery
- T1083 File and Directory Discovery
- T1005 Data from Local System
- T1119 Automated Collection
- T1041 Exfiltration Over C2 Channel
- T1210 Exploitation of Remote Services
- T1565.001 Stored Data Manipulation
- T1505.003 Web Shell
- T1068 Exploitation for Privilege Escalation
- T1587.004 Exploits

## Sources

- [Attackers target critical FortiSandbox flaws as CISA issues patch order](https://www.theregister.com/security/2026/07/17/attackers-target-critical-fortisandbox-flaws-as-cisa-issues-patch-order/5274287)
- [CISA warns feds to patch exploited Fortinet FortiSandbox flaws by Sunday](https://www.bleepingcomputer.com/news/security/cisa-warns-feds-to-patch-exploited-fortinet-fortisandbox-flaws-by-sunday/)
- [Attackers are exploiting FortiSandbox vulnerabilities](https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/)
- [Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808)](https://www.helpnetsecurity.com/2026/04/16/fortinet-fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808/)
- [Fortinet FortiSandbox Vulnerability Exploited by Attackers (CVE-2026-39808, CVE-2026-25089, & CVE-2026-39813)](https://threatprotect.qualys.com/2026/06/17/fortinet-fortisandbox-vulnerability-exploited-by-attackers-cve-2026-39808-cve-2026-25089-cve-2026-39813/)
- [Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week](https://thehackernews.com/2026/06/attackers-exploit-three-fortinet.html)
- [FG-IR-26-141 - PSIRT | FortiGuard Labs](https://fortiguard.fortinet.com/psirt/FG-IR-26-141)
- [CVE-2026-39813 - PSIRT | FortiGuard Labs](https://fortiguard.fortinet.com/psirt/FG-IR-26-112)
- [CVE-2026-39813 Deep Dive: Path Traversal Authentication Bypass in FortiSandbox JRPC API](https://rustlang.rs/posts/blog_cve_2026_39813_en/)
- [FortiSandbox Vulnerabilities Expose Systems to Auth Bypass and Command Execution](https://socradar.io/blog/fortisandbox-system-auth-bypass-command-execution/)
- [GitHub - error-inside/CVE-2026-39808: Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint](https://github.com/error-inside/CVE-2026-39808)
- [FortiSandbox Root Sandbox Escape - CVE-2026-39808](https://github.com/0xBlackash/CVE-2026-39808)
- [CVE-2026-25089: Fortinet FortiSandbox Unauthenticated OS Command Injection — How to Find Exposed Instances on Your Network](https://hellorecon.com/blog/cve-2026-25089)
- [3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs](https://www.securityweek.com/3-recently-patched-fortinet-fortisandbox-vulnerabilities-in-hacker-crosshairs/)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1447
