logo

Critical Fortinet FortiSandbox Vulnerabilities Exploited in the Wild

ID: a190ec11-4382-568e-8b8d-9f5efd48e146

STIX ID: report--a190ec11-4382-568e-8b8d-9f5efd48e146

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Lucas Martin

...
...

Multiple critical FortiSandbox vulnerabilities (notably CVE-2026-39813 and CVE-2026-39808, both CVSS 9.8) are being actively exploited in the wild; attackers are sending crafted JSONRPC POST requests to /jsonrpc/ from IP 141.11.43.175 (ASN AS136510) and using unauthenticated paths to achieve privilege escalation or root command execution. Fortinet issued patches in April 2026; organizations are advised to immediately upgrade affected FortiSandbox versions to 4.4.9 or 5.0.6, block the hostile ASN where appropriate, and monitor for anomalous /jsonrpc/ traffic and lateral movement originating from sandbox hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.