logo

CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands

ID: 90d9b8a8-2002-5410-b2ae-ae7db6d76894

STIX ID: report--90d9b8a8-2002-5410-b2ae-ae7db6d76894

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Divya

...
...

**Executive summary:** CISA added two critical Fortinet FortiSandbox vulnerabilities (CVE-2026-39808 and CVE-2026-25089) to its Known Exploited Vulnerabilities catalog; both are unauthenticated OS command injection flaws being actively exploited in the wild and affecting FortiSandbox appliances as well as FortiSandbox Cloud and PaaS, potentially allowing full system compromise, tampering with malware analysis, and lateral movement — CISA mandates federal remediation by July 19, 2026 and urges immediate mitigations, exposure assessments, forensic triage, and monitoring for indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.