Patch these critical Fortinet sandbox bugs that let attackers bypass login, run commands over HTTP
ID: 292e5f53-46ba-5128-aa06-b13b3f428c66
STIX ID: report--292e5f53-46ba-5128-aa06-b13b3f428c66
Feed Name: The Register (Security)
Threat Score
Two critical FortiSandbox vulnerabilities (CVE-2026-39808: unauthenticated OS command injection; CVE-2026-39813: JRPC API path traversal enabling authentication bypass) affecting multiple 4.4.x and 5.0.x releases have been disclosed and scored CVSS 9.1; Fortinet has released patches (4.4.9+/5.0.6+) and public scanners are available to detect vulnerable instances, increasing the risk of rapid exploitation despite no reports of active attacks so far.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
