Fortinet issued multiple 2026 security advisories covering a broad set of vulnerabilities across FortiSandbox, FortiManager, FortiAnalyzer, FortiOS, FortiAP, FortiProxy, FortiPAM, FortiSwitchManager, FortiSwitchAXFixed, and related cloud offerings. The most severe flaws affect FortiSandbox, including CVE-2026-39808, an unauthenticated OS command injection bug that could allow arbitrary command execution and full device compromise, CVE-2026-39813, a path traversal issue in the JRPC API that may enable authentication bypass and privilege escalation, and CVE-2026-26083, a missing authorization flaw that can expose restricted functionality and sensitive sandbox analysis data through the GUI without authentication. National cyber authorities in Canada and Belgium separately warned organizations to apply Fortinet’s fixes immediately.
Fortinet also disclosed high-risk issues in management platforms, notably CVE-2025-54820, a stack-based buffer overflow in the FortiManager fgtupdates service that can let remote unauthenticated attackers execute unauthorized commands when the service is enabled, as well as a heap-based buffer overflow affecting FortiAnalyzer Cloud and FortiManager Cloud. Additional weaknesses across the product line include authentication and MFA bypasses, SQL injection, API denial of service, CLI command injection in FortiAP, CAPWAP daemon memory corruption in FortiOS, stored and reflected XSS, improper access control, and credential exposure. Fortinet advised customers to upgrade to fixed releases, disable exposed services such as fgtupdates where possible, restrict CLI, SSH, and API access, and monitor logs for anomalous authentication, privilege escalation, and endpoint activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-16, BleepingComputer reported Defused had observed active exploitation of multiple critical Fortinet FortiSandbox vulnerabilities, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The report said exploitation was seen within the previous 24 hours, marking a shift from disclosed vulnerabilities to confirmed in-the-wild attacks.
On 2026-06-11, Belgium's Centre for Cybersecurity published an advisory warning about Fortinet's critical FortiSandbox command injection vulnerability and urged organizations to patch immediately. The notice concerns the FortiSandbox flaw previously disclosed by Fortinet affecting FortiSandbox products.
Researchers at VulnCheck first observed active exploitation of FortiSandbox vulnerability CVE-2026-39808 on 2026-06-09. The later CyberScoop report said this exploitation began after Fortinet had disclosed and patched the flaw in April.
On 2026-06-09, Fortinet published advisory FG-IR-26-141 for CVE-2026-25089, a critical OS command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. The flaw allows unauthenticated remote attackers to execute arbitrary operating system commands via the web interface, and Fortinet issued fixed-version and mitigation guidance.
On 2026-05-14, Belgium's Centre for Cybersecurity issued an advisory warning about multiple critical, high, and medium vulnerabilities in Fortinet FortiSandbox, FortiOS, FortiAP, FortiAnalyzer, and FortiManager. The notice urged immediate patching.
On 2026-05-12, Fortinet published security advisories for five vulnerabilities affecting FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS, FortiAP, FortiAnalyzer, FortiManager, and FortiOS. The most severe was CVE-2026-26083, a critical missing authorization flaw in FortiSandbox products that could be exploited remotely without authentication through the GUI to access restricted functionality or sensitive analysis data.
On 2026-04-14, Fortinet released security advisories addressing 11 vulnerabilities across FortiSandbox, FortiAnalyzer Cloud, FortiManager Cloud, FortiOS, FortiProxy, FortiPAM, FortiSwitchManager, and FortiDDoS-F. The most serious issues included critical unauthenticated FortiSandbox flaws enabling command execution, authentication bypass, and privilege escalation, plus a high-severity heap-based buffer overflow in cloud products.
On 2026-03-10, Fortinet published advisory FG-IR-26-098 for CVE-2025-54820, a high-severity stack-based buffer overflow in the FortiManager fgtupdates service. The flaw could allow remote unauthenticated attackers to execute unauthorized commands under certain conditions, and Fortinet provided fixed-version guidance and a workaround to disable fgtupdates.
On 2026-03-10, Fortinet published security advisories covering eleven vulnerabilities affecting products including FortiManager, FortiAnalyzer, FortiSwitchAXFixed, and FortiSandbox/FortiSandbox Cloud. The issues included buffer overflows, authentication and MFA bypasses, TLS validation weaknesses, OS command injection, privilege escalation, SQL injection, format string exposure, and stored XSS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
22 references tracked. Mallory keeps watching after this page renders.
linuxsecurity.com
Open sourcecyberscoop.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcecyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.