logo

Critical FortiSandbox Vulnerabilities Allow Attackers to Execute Unauthorized Commands

ID: 88df80d3-9cfc-564b-804b-78995071f49e

STIX ID: report--88df80d3-9cfc-564b-804b-78995071f49e

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Fortinet disclosed two critical FortiSandbox vulnerabilities (CVE-2026-39808: OS command injection in the API; CVE-2026-39813: authentication bypass via JRPC path traversal), each scored CVSSv3 9.1 and allowing unauthenticated remote attackers to execute commands or bypass auth. Affected FortiSandbox 4.4 and 5.0 versions are listed with recommended upgrades (4.4.9+, 5.0.6+), and organizations are urged to patch, audit deployments, and restrict API access; no active exploitation was reported at publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.