logo

Patch these critical Fortinet sandbox bugs that let attackers bypass login, run commands over HTTP

ID: 292e5f53-46ba-5128-aa06-b13b3f428c66

STIX ID: report--292e5f53-46ba-5128-aa06-b13b3f428c66

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-04-15

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Two critical FortiSandbox vulnerabilities (CVE-2026-39808: unauthenticated OS command injection; CVE-2026-39813: JRPC API path traversal enabling authentication bypass) affecting multiple 4.4.x and 5.0.x releases have been disclosed and scored CVSS 9.1; Fortinet has released patches (4.4.9+/5.0.6+) and public scanners are available to detect vulnerable instances, increasing the risk of rapid exploitation despite no reports of active attacks so far.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.