Critical FortiSandbox Vulnerabilities Allow Attackers to Execute Unauthorized Commands
ID: 88df80d3-9cfc-564b-804b-78995071f49e
STIX ID: report--88df80d3-9cfc-564b-804b-78995071f49e
Feed Name: cybersecurityNews.com
Fortinet disclosed two critical FortiSandbox vulnerabilities (CVE-2026-39808: OS command injection in the API; CVE-2026-39813: authentication bypass via JRPC path traversal), each scored CVSSv3 9.1 and allowing unauthenticated remote attackers to execute commands or bypass auth. Affected FortiSandbox 4.4 and 5.0 versions are listed with recommended upgrades (4.4.9+, 5.0.6+), and organizations are urged to patch, audit deployments, and restrict API access; no active exploitation was reported at publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
