Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks
ID: a7c142a8-5030-53af-b159-2772d7e576a5
STIX ID: report--a7c142a8-5030-53af-b159-2772d7e576a5
Feed Name: cybersecurityNews.com
**Executive Summary:** Threat actors are actively exploiting multiple critical, unauthenticated vulnerabilities in FortiSandbox (including a newly observed path traversal CVE-2026-39813 and command injection CVE-2026-39808) via crafted POST requests to /jsonrpc/, with live telemetry and IOCs (attacker IP 141.11.43.175, ASN AS136510, target port 443, user-agent) confirming ongoing attacks that can enable root execution, lateral movement, and approval of malicious files in dependent Fortinet systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
