OS Command Injection Vulnerability in Fortinet FortiSandbox
CVE-2026-39808

9.1CRITICAL

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
14 April 2026

Badges

📈 Trended📈 Score: 1,660👾 Exploit Exists🟡 Public PoC🟣 EPSS 84%🦅 CISA Reported📰 News Worthy

What is CVE-2026-39808?

CVE-2026-39808 is a notable vulnerability affecting Fortinet's FortiSandbox, a security appliance designed to provide advanced threat detection and prevention by analyzing potentially malicious files in a controlled environment. This specific vulnerability arises from improper neutralization of special elements, leading to an OS command injection flaw. Such a weakness enables attackers to execute unauthorized commands on the underlying operating system. The potential for code execution could allow malicious users to manipulate system processes, access sensitive data, or even maintain persistent control over affected systems. The severity of this vulnerability is particularly concerning for organizations relying on FortiSandbox for cybersecurity, as it may compromise the integrity of their defenses against sophisticated threats.

Potential Impact of CVE-2026-39808

  1. Unauthorized Command Execution: The successful exploitation of this vulnerability can allow attackers to execute arbitrary commands on the affected systems, potentially leading to unauthorized access and control.

  2. Data Compromise: With the ability to run unauthorized commands, attackers might gain access to sensitive data stored within FortiSandbox or connected networks, exposing organizations to data breaches.

  3. System Integrity Threat: The exploitation could lead to modifications or manipulations of system settings and configurations, undermining the overall security posture of the organization and causing disruptions in normal operational functions.

CISA has reported CVE-2026-39808

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-39808 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

FortiSandbox 4.4.0 <= 4.4.8

FortiSandbox PaaS 23.4.4374

FortiSandbox PaaS 23.4.4350

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

US Cybersecurity Agency Sounds Alarm, Orders Immediate Action on Actively Exploited Fortinet Flaws

CISA has ordered US agencies to urgently patch actively exploited Fortinet vulnerabilities, warning the critical flaws could enable remote code execution...

4 days ago

3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs

Fortinet FortiSandbox vulnerabilities tracked as CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089 are being targeted in the wild.

Attackers are exploiting FortiSandbox vulnerabilities - IT Security News

Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from...

References

EPSS Score

84% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🦅

    CISA Reported

  • 📈

    Vulnerability started trending

  • 📰

    First article discovered by It Security News

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.