logo

Attackers are exploiting FortiSandbox vulnerabilities

ID: b79f3596-7f06-5420-bc71-ead9515714bb

STIX ID: report--b79f3596-7f06-5420-bc71-ead9515714bb

Feed Name: Help Net Security

Threat Score
65/100

Date Published: 2026-06-16

Date Updated: 2026-06-17

Author: Zeljka Zorz

...
...

Attackers have been observed exploiting three FortiSandbox vulnerabilities — a JRPC API path traversal allowing potential authentication bypass (CVE-2026-39813) and two OS command injection flaws (CVE-2026-39808 and CVE-2026-25089) that could permit unauthenticated command execution; Fortinet has issued fixes but public details of attacks are limited and one available exploit appears faulty.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.