Attackers are actively exploiting three critical FortiSandbox vulnerabilities—CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089—to compromise exposed appliances through crafted HTTP requests. The flaws affect FortiSandbox 4.4.0 through 4.4.8 and 5.0.0 through 5.0.5, while CVE-2026-25089 also impacts FortiSandbox Cloud and FortiSandbox PaaS 5.0.4 through 5.0.5. Reported attack chains include path traversal leading to authentication bypass and OS command injection enabling arbitrary command execution, with all three issues carrying a CVSS 9.1 severity rating.
Fortinet issued fixes for CVE-2026-39813 and CVE-2026-39808 in April and patched CVE-2026-25089 in a broader June security update that also covered other Fortinet products, including FortiOS, FortiProxy, and FortiPortal. Remediation is available in FortiSandbox 4.4.9, 5.0.6, and 5.2.0 or later, and organizations were urged to deploy updates quickly after testing because a FortiSandbox compromise could corrupt threat verdicts consumed by other Fortinet security products and weaken defenses across the wider Fortinet ecosystem.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-16, ThreatAft reported that three critical FortiSandbox vulnerabilities were being actively exploited in the wild. The report noted Fortinet had patched CVE-2026-39813 and CVE-2026-39808 in April 2026 and CVE-2026-25089 in June 2026, with fixes available in versions 4.4.9, 5.0.6, and 5.2.0 or later.
Defused reported observing active exploitation of three FortiSandbox vulnerabilities—CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089—during a 24-hour period beginning over the weekend. The attacks used crafted HTTP requests to achieve authentication bypass and OS command injection.
On 2026-06-10, Ivanti released security updates for Endpoint Manager Mobile and Ivanti Sentry to remediate multiple vulnerabilities. The update addressed critical flaws including CVE-2026-10520 and CVE-2026-10523 affecting supported and earlier versions listed in the advisory.
On 2026-06-10, Fortinet released security updates for multiple products, including a fix for FortiSandbox vulnerability CVE-2026-25089. The updates covered FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS, FortiOS, FortiProxy, and FortiPortal.
On 2026-06-09, Apache released a security update for Apache HTTP Server to fix multiple vulnerabilities affecting version 2.4.67 and earlier, including CVE-2026-44631 and CVE-2026-29170. The issues were addressed in version 2.4.68.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt.org.eg
Open sourceegfincirt-wpn.azurewebsites.net
Open sourcezeropath.com
Open sourceegfincirt.org.eg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.