CISA added Fortinet FortiSandbox vulnerabilities CVE-2026-25089 and CVE-2026-39808 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation, elevating urgency around two critical unauthenticated OS command injection bugs that can be triggered through crafted HTTP requests. The flaws affect multiple FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS versions and can allow arbitrary command execution, creating a path to full remote compromise of sandbox appliances that many organizations rely on for malware analysis and detection workflows.
Fortinet published a PSIRT advisory for the issue, while third-party reporting said exploitation attempts were observed in June before the KEV listing. Available fixes include FortiSandbox 5.0.6 and 4.4.9, and CISA has ordered federal civilian agencies to remediate the vulnerabilities on an accelerated timeline under its binding directives. Security researchers warned that a compromised FortiSandbox deployment could create a dangerous detection blind spot while also giving attackers a foothold deeper inside enterprise networks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Security Online reported that Defused observed exploitation attempts against CVE-2026-25089 and CVE-2026-39808 in June. At that time, Fortinet had not confirmed in-the-wild exploitation.
On July 16, 2026, CISA added CVE-2026-25089 and CVE-2026-39808 to its Known Exploited Vulnerabilities catalog, identifying them as actively exploited. Reporting notes that patches were already available and federal agencies were required to remediate under Binding Operational Directive requirements.
Fortinet published PSIRT advisory FG-IR-26-146 covering the FortiSandbox vulnerabilities CVE-2026-25089 and CVE-2026-39808. The advisory corresponds to fixes available for affected FortiSandbox products.
Fortinet had already issued fixes for the FortiSandbox flaws later tracked as CVE-2026-39808 and CVE-2026-25089. The reference states the patches were released on April 14 and June 9, before CISA added the bugs to the KEV catalog.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcethreataft.com
Open sourcebleepingcomputer.com
Open sourcetheregister.com
Open sourcefortiguard.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.