logo

Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

ID: ef480f8a-06b5-5d6e-b199-9f2779147e0d

STIX ID: report--ef480f8a-06b5-5d6e-b199-9f2779147e0d

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: [email protected] (The Hacker News)

...
...

Threat intelligence firm Defused Cyber observed exploitation of multiple high-severity FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) over a 24-hour period; the flaws (CVSS 9.1) enable unauthenticated path traversal and OS command injection, Fortinet has issued patches (April 2026 and last week), and one observed exploit shows signs of being AI-developed though a working public exploit has not been disclosed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.