CVE-2026-39808Active Exploitation(fortinet / fortisandbox)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 12 mentions and remains active

Immediate actions

  • Patch fortinet fortisandbox systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-07-19. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-78

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortisandbox

Threat summary

  • Active exploitation appears in 51 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 120 mentions across 39 observed days

What's happening

  • Active exploitation reported across 51 signals
  • Exploit tool or code specified in 18 signals
  • PoC mentioned or linked in 30 signals
  • Patch or workaround mentioned in 57 signals
  • Technical details provided in 82 signals
  • Disclosure: 22 classified signals
  • Peaked 8d ago at 12 mentions (2026-07-17); latest day: 1
  • 120 total mentions across 39 days

Affected systems

Vendors
Products
fortisandbox

Deep dive

Activity timeline120 mentions / 39d
036912Mentions · 2026-04-14: 4Mentions · 2026-04-15: 8Mentions · 2026-04-16: 9Mentions · 2026-04-17: 6Mentions · 2026-04-18: 6Mentions · 2026-04-19: 4Mentions · 2026-04-20: 5Mentions · 2026-04-21: 7Mentions · 2026-04-22: 3Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Mentions · 2026-04-26: 2Mentions · 2026-04-27: 1Mentions · 2026-04-29: 1Mentions · 2026-05-02: 1Mentions · 2026-05-12: 1Mentions · 2026-06-13: 1Mentions · 2026-06-15: 1Mentions · 2026-06-16: 9Mentions · 2026-06-17: 9Mentions · 2026-06-18: 2Mentions · 2026-06-21: 1Mentions · 2026-06-22: 1Mentions · 2026-06-23: 1Mentions · 2026-06-26: 1Mentions · 2026-06-27: 3Mentions · 2026-06-29: 1Mentions · 2026-07-04: 1Mentions · 2026-07-08: 1Mentions · 2026-07-16: 5Mentions · 2026-07-17: 12Mentions · 2026-07-18: 4Mentions · 2026-07-19: 1Mentions · 2026-07-21: 1Mentions · 2026-07-22: 1Mentions · 2026-07-24: 1Mentions · 2026-07-25: 1Mentions · 2026-08-05: 1Mentions · 2026-08-16: 1PoC Mentioned / Linked · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-16: 1PoC Mentioned / Linked · 2026-04-17: 3PoC Mentioned / Linked · 2026-04-18: 4PoC Mentioned / Linked · 2026-04-19: 3PoC Mentioned / Linked · 2026-04-20: 3PoC Mentioned / Linked · 2026-04-21: 6PoC Mentioned / Linked · 2026-04-22: 1PoC Mentioned / Linked · 2026-04-24: 1PoC Mentioned / Linked · 2026-04-26: 1PoC Mentioned / Linked · 2026-04-29: 1PoC Mentioned / Linked · 2026-05-12: 1PoC Mentioned / Linked · 2026-06-16: 1PoC Mentioned / Linked · 2026-07-16: 1PoC Mentioned / Linked · 2026-07-17: 1Exploit Tool / Code · 2026-04-16: 1Exploit Tool / Code · 2026-04-17: 2Exploit Tool / Code · 2026-04-18: 1Exploit Tool / Code · 2026-04-19: 1Exploit Tool / Code · 2026-04-20: 3Exploit Tool / Code · 2026-04-21: 4Exploit Tool / Code · 2026-04-24: 1Exploit Tool / Code · 2026-04-26: 1Exploit Tool / Code · 2026-04-29: 1Exploit Tool / Code · 2026-05-12: 1Exploit Tool / Code · 2026-06-16: 1Exploit Tool / Code · 2026-07-16: 1Active Exploitation · 2026-04-19: 1Active Exploitation · 2026-04-21: 2Active Exploitation · 2026-06-13: 1Active Exploitation · 2026-06-15: 1Active Exploitation · 2026-06-16: 9Active Exploitation · 2026-06-17: 9Active Exploitation · 2026-06-18: 2Active Exploitation · 2026-06-23: 1Active Exploitation · 2026-06-27: 1Active Exploitation · 2026-06-29: 1Active Exploitation · 2026-07-16: 4Active Exploitation · 2026-07-17: 10Active Exploitation · 2026-07-18: 4Active Exploitation · 2026-07-19: 1Active Exploitation · 2026-07-21: 1Active Exploitation · 2026-07-24: 1Active Exploitation · 2026-07-25: 1Active Exploitation · 2026-08-16: 1Patch / Workaround · 2026-04-14: 2Patch / Workaround · 2026-04-15: 6Patch / Workaround · 2026-04-16: 7Patch / Workaround · 2026-04-17: 2Patch / Workaround · 2026-04-18: 3Patch / Workaround · 2026-04-19: 3Patch / Workaround · 2026-04-20: 4Patch / Workaround · 2026-04-21: 5Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-06-16: 3Patch / Workaround · 2026-06-17: 4Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-27: 1Patch / Workaround · 2026-07-16: 4Patch / Workaround · 2026-07-17: 5Patch / Workaround · 2026-07-18: 3Patch / Workaround · 2026-07-21: 1Patch / Workaround · 2026-08-16: 1Technical Details · 2026-04-14: 4Technical Details · 2026-04-15: 8Technical Details · 2026-04-16: 4Technical Details · 2026-04-17: 4Technical Details · 2026-04-18: 6Technical Details · 2026-04-19: 4Technical Details · 2026-04-20: 4Technical Details · 2026-04-21: 6Technical Details · 2026-04-22: 2Technical Details · 2026-04-23: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-26: 2Technical Details · 2026-05-02: 1Technical Details · 2026-05-12: 1Technical Details · 2026-06-16: 6Technical Details · 2026-06-17: 4Technical Details · 2026-06-18: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-29: 1Technical Details · 2026-07-16: 4Technical Details · 2026-07-17: 10Technical Details · 2026-07-18: 3Technical Details · 2026-07-21: 1Technical Details · 2026-07-24: 1Technical Details · 2026-08-05: 1Technical Details · 2026-08-16: 104-1404-1704-2004-2304-2705-1206-1606-2106-2607-0407-1707-2107-2508-16
Signal classification7 categories
Active Exploitation
4739.2%
Patch
2319.2%
Disclosure
2218.3%
PoC
1512.5%
General
86.7%
Exploit
43.3%
Referenced assets117 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-144
Disclosure3General1
2026-04-158
Disclosure3Patch5
2026-04-169
Disclosure1General1Patch7
2026-04-176
General1Patch2PoC3
2026-04-186
Patch2PoC4
2026-04-194
Active Exploitation1Disclosure1PoC2
2026-04-205
Disclosure1Patch1PoC3
2026-04-217
Active Exploitation1Disclosure1Exploit2Patch1PoC2
2026-04-223
Disclosure2General1
2026-04-231
Disclosure1
2026-04-241
PoC1
2026-04-262
Disclosure1Exploit1
2026-04-271
General1
2026-04-291
Exploit1
2026-05-021
Disclosure1
2026-05-121
Patch1
2026-06-131
Active Exploitation1
2026-06-151
Active Exploitation1
2026-06-169
Active Exploitation9
2026-06-179
Active Exploitation9
2026-06-182
Active Exploitation2
2026-06-211
General1
2026-06-221
Disclousure1
2026-06-231
Active Exploitation1
2026-06-261
General1
2026-06-273
Active Exploitation1Disclosure2
2026-06-291
Active Exploitation1
2026-07-041
Disclosure1
2026-07-081
Disclosure1
2026-07-165
Active Exploitation4Patch1
2026-07-1712
Active Exploitation9Disclosure1Patch2
2026-07-184
Active Exploitation3Disclosure1
2026-07-191
Active Exploitation1
2026-07-211
Patch1
2026-07-221
General1
2026-07-241
Active Exploitation1
2026-07-251
Active Exploitation1
2026-08-051
Disclosure1
2026-08-161
Active Exploitation1
Full discourse20 posts
  • Rishi@rxerium
    Disclosure

    🚨 Fortinet just disclosed CVE-2026-39808 and CVE-2026-39813 - 2 critical vulnerabilities affecting FortiSandbox. No active exploitation itw reported as of yet. Scan your infrastructure to find vulnerable instances: CVE-2026-39808: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-39808.yaml CVE-2026-39813: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-39813.yaml CVE-2026-39808 (CVSS 9.1): An Improper Neutralization of Special Elements used in an OS Command ('OS command injection') vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. CVE-2026-39813 (CVSS 9.1): A Path Traversal vulnerability [CWE-24] in FortiSandbox JRPC API may allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests. Patches are available as per vendor advisories: https://fortiguard.fortinet.com/psirt/FG-IR-26-112 https://fortiguard.fortinet.com/psirt/FG-IR-26-100

    Post summary

    Fortinet disclosed two critical vulnerabilities in FortiSandbox, with PoC templates and vendor patches linked; no active exploitation has been reported.

    269628313547.5K
    3.8K followersView on X
  • Bipin Jitiya@win3zz
    PoC

    CVE-2026-39808 - Critical OS Command Injection in Fortinet FortiSandbox ⚠️Unauthenticated → root RCE via a single crafted HTTP request (jid param goes straight to shell, classic!) Patched in 4.4.9+ PoC Ref: https://www.linkedin.com/posts/samuel-delucas_in-november-2025-i-discovered-a-critical-activity-7450108628193234944-mTc5 https://t.co/NAHYeObFX1

    Post summary

    The tweet announces CVE-2026-39808, a critical OS command injection in Fortinet FortiSandbox, provides a PoC link, details the unauthenticated root RCE via a crafted HTTP request, and notes that it was patched in version 4.4.9+.

    347022710621.2K
    7.9K followersView on X
  • Yunus Emre Öztaş@ynsmroztas
    Exploit

    Just dropped a scanner for CVE-2026-39808 🔥 FortiSandbox < 4.4.9 — Unauthenticated RCE as root The jid parameter in /fortisandbox/job-detail/tracer-behavior is vulnerable to OS command injection. No auth. No complexity. Just pipe and execute. CVSS: 9.8 💀 Tool features: → Canary-based detection (no false positives) → Pipeline ready: subfinder | httpx | fortisandbox_rce.py → Zero pip dependencies → Burp proxy & JSON export Patch now → FortiSandbox 4.4.9+ 🔗 https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808 #BugBounty #InfoSec #CVE202639808 #Fortinet #RedTeam #AppSec #bugbountytip #bugbountytips #infosec #recon

    Post summary

    The post announces a scanner and functional exploit for FortiSandbox CVE-2026-39808, provides a GitHub link to the code, details the vulnerability type and CVSS score, and notes the available patch.

    2191126839.8K
    7.7K followersView on X
  • Cyber Security News@The_Cyber_News
    PoC

    🚨 PoC Exploit for FortiSandbox Vulnerability Allows Command Execution Source: https://cybersecuritynews.com/poc-exploit-fortisandbox-vulnerability/ A proof-of-concept (PoC) exploit has been publicly released for a critical vulnerability in Fortinet’s FortiSandbox product, tracked as CVE-2026-39808. The flaw allows an unauthenticated attacker to execute arbitrary operating system commands as root, the highest privilege level, without requiring any login credentials. An attacker can inject malicious operating system commands through the jid GET parameter by using the pipe symbol (|) a common technique used to chain commands in Unix-based systems. #cybersecuritynews

    Post summary

    A publicly released PoC exploit for CVE‑2026‑39808 in FortiSandbox enables unauthenticated root command execution via GET parameter injection, though no active exploitation or patch is reported.

    3312120207.4K
    67.1K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CVE-2026-39808: An unspecified API in FortiSandbox versions 4.4.0 through 4.4.8, allowing unauthenticated code/command execution by taking advantage of improper neutralization of special elements used in an OS command. CVSS: 9.1 GitHub: https://github.com/samu-delucas/CVE-2026-39808 curl command is at the bottom of the page.

    Post summary

    The text announces a new critical vulnerability (CVE-2026-39808) affecting FortiSandbox versions 4.4.0–4.4.8, provides technical details and CVSS score, and shares a GitHub PoC with a curl command.

    2220844010.6K
    221.5K followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    CISA has added two critical Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, warning that attackers are actively exploiting the flaws in real-world attacks. The vulnerabilities, identified as CVE-2026-39808 and CVE-2026-25089, allow unauthenticated attackers to execute unauthorized operating system commands through specially crafted HTTP requests. Both issues are classified as OS command injection vulnerabilities, which occur when an application fails to properly sanitize user-controlled input.

    Post summary

    CISA reports that two critical OS command‑injection vulnerabilities in Fortinet FortiSandbox are being actively exploited in the wild, highlighting the high risk posed by CVE‑2026‑39808 and CVE‑2026‑25089.

    329098176.6K
    72.8K followersView on X
  • Rishi@rxerium
    Active Exploitation

    CVE-2026-39808 is now seeing active exploitation according to Vulncheck. Scan your infrastructure to see if you're vulnerable:

    Post summary

    The tweet announces that CVE-2026-39808 is reportedly being exploited in the wild, but it offers no technical or remedial details. The claim is based solely on a Vulncheck reference.

    115084468.8K
    3.8K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨We are observing exploitation of multiple Fortinet FortiSandbox vulnerabilities during the past 24 hours, including: CVE-2026-39813 (no previous recorded exploitation) CVE-2026-39808 CVE-2026-25089 (vibecoded, likely faulty exploit) Per our research a working exploit for CVE-2026-25089 has not yet been publicly disclosed. Track FortiSandbox exploitation 👉 https://console.defusedcyber.com/signup

    Post summary

    The post reports ongoing exploitation of several Fortinet FortiSandbox CVEs within the last day, but gives no evidence of PoC code, patches, or detailed technical data.

    217254166.9K
    7.6K followersView on X
  • Hunter@HunterMapping
    General

    🚨Alert🚨 CVE-2026-39808 & CVE-2026-39813 : 2 critical vulnerabilities affecting FortiSandbox. 📊 203 Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22FortiSandbox%22 👇Query HUNTER : http://product.name="FortiSandbox" 📰Refer:https://securityonline.info/fortinet-fortisandbox-critical-vulnerability-cve-2026-39813-cve-2026-39808/ https://fortiguard.fortinet.com/psirt/FG-IR-26-100 https://fortiguard.fortinet.com/psirt/FG-IR-26-112 #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces two critical CVEs against FortiSandbox, cites reference links, but offers no PoC, exploit code, active exploitation details, or patch information.

    02103883.3K
    25.9K followersView on X
  • Cristian Borghello@SeguInfo
    Disclosure

    Como diría alguien (de #Fortinet): "que MAL que la estoy pasando"😤 - CVE-2026-21643 - Inyección SQL (9.1) - CVE-2026-35616 - Control de acceso inadecuado (9.1) - CVE-2026-39808 - Ejecución de comandos (9.1) 🔗https://blog.segu-info.com.ar/2026/04/otra-vulnerabilidad-critica-rce-en.html PARCHEA!

    Post summary

    The post announces three high‑severity CVEs (SQL injection, access‑control, command execution), lists their types and scores, references a blog for details, and urges users to apply patches.

    012038152.9K
    38.3K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️We added Fortinet FortiSandbox vulnerabilities CVE-2026-25089 &amp; CVE-2026-39808 and Microsoft SharePoint vulnerability CVE-2026-58644 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q &amp; apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/jfzm47JWjo

    Post summary

    The post announces the addition of three CVEs—CVE-2026-25089, CVE-2026-39808 (Fortinet FortiSandbox) and CVE-2026-58644 (Microsoft SharePoint)—to the KEV catalog, signaling that these vulnerabilities are actively exploited, and urges the audience to deploy mitigations.

    61213548.4K
    302.1K followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    Critical 9.1 CVSS flaw in FortiSandbox: Full PoC &amp; details for CVE-2026-39808 are now public. Unauthenticated root RCE is possible. Upgrade to 4.4.9 immediately. #FortiSandbox #CVE202639808 #PoC #RCE #CyberSecurity #Fortinet #Infosec #Exploit https://securityonline.info/fortisandbox-cve-2026-39808-rce-poc-exploit-disclosure/ https://t.co/NZVruA0Qjq

    Post summary

    A publicly released PoC demonstrates unauthenticated root RCE in FortiSandbox (CVE-2026-39808), rated CVSS 9.1, and the vendor recommends upgrading to version 4.4.9 to remediate the issue.

    111035113.2K
    12.5K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(7/16追加) CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / Fortinet, Inc. (CNA) ・種別:OSコマンドインジェクション (CWE-78) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Fortinet FortiSandbox、FortiSandbox Cloud、FortiSandbox PaaS に存在する OS コマンドインジェクションの脆弱性です。 FortiSandbox の start vnc 機能における JSON 入力処理に問題があり、未認証のリモート攻撃者が細工した HTTP リクエストを送信することで、不正なコマンドを実行できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月19日 ・BOD 26-04 対処期限(露出なし):2026年7月30日 ✅攻撃前提条件 ・Fortinet FortiSandbox、FortiSandbox Cloud、または FortiSandbox PaaS を使用している ・影響を受けるバージョンを使用している ・攻撃者が対象の FortiSandbox WEB UI へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・修正済みバージョンへ更新されていない ✅悪用時影響 ・FortiSandbox 上で任意の OS コマンドを実行される可能性がある ・FortiSandbox の管理機能または分析基盤を不正操作される可能性がある ・セキュリティ分析基盤を侵害され、検知回避や追加侵害の足掛かりに利用される可能性がある ・機密性、完全性、可用性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(Defused) ・概要:Defused Cyber が共有した脅威インテリジェンスでは、CVE-2026-25089 を含む FortiSandbox 脆弱性群に対する悪用開始を報告。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-25089 ・https://fortiguard.fortinet.com/psirt/FG-IR-26-141 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/25xxx/CVE-2026-25089.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-25089 ・https://www.yazoul.net/advisory/cve/cve-2026-25089-fortisandbox-unauth-rce-poc/ ・https://iototsecnews.jp/2026/06/16/hackers-exploit-critical-fortinet-fortisandbox-flaws-in-active-attacks/ ・https://jvndb.jvn.jp/ja/cwe/CWE-78.html CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / Fortinet, Inc. (CNA) ・種別:OSコマンドインジェクション (CWE-78) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Fortinet FortiSandbox に存在する OS コマンドインジェクションの脆弱性です。 FortiSandbox の API エンドポイントにおける入力処理に問題があり、未認証のリモート攻撃者が細工した HTTP リクエストを送信することで、不正なコードまたはコマンドを実行できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月19日 ・BOD 26-04 対処期限(露出なし):2026年7月30日 ✅攻撃前提条件 ・Fortinet FortiSandbox 4.4.0 から 4.4.8 までの影響を受けるバージョンを使用している ・攻撃者が対象の FortiSandbox API エンドポイントへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・FortiSandbox 4.4.9 以降へ更新されていない ✅悪用時影響 ・FortiSandbox 上で不正なコードまたは OS コマンドを実行される可能性がある ・root 権限でコマンドを実行される可能性がある ・FortiSandbox の分析結果や管理機能を不正操作される可能性がある ・セキュリティ分析基盤を起点に追加侵害へつなげられる可能性がある ・機密性、完全性、可用性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:確認済み(Defused) ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-39808 ・https://fortiguard.fortinet.com/psirt/FG-IR-26-100 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/39xxx/CVE-2026-39808.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-39808 ・https://github.com/samu-delucas/CVE-2026-39808 CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / Microsoft Corporation (CNA) ・種別:信頼できないデータのデシリアライゼーション (CWE-502) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Microsoft Office SharePoint に存在する、信頼できないデータのデシリアライゼーションに起因するリモートコード実行の脆弱性です。 未認証の攻撃者がネットワーク経由で悪用することで、SharePoint 上でコードを実行できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月19日 ・BOD 26-04 対処期限(露出なし):2026年7月30日 ✅攻撃前提条件 ・Microsoft SharePoint Enterprise Server 2016、Microsoft SharePoint Server 2019、または Microsoft SharePoint Server Subscription Edition を使用している ・SharePoint Enterprise Server 2016 で 16.0.5556.1005 未満を使用している ・SharePoint Server 2019 で 16.0.10417.20153 未満を使用している ・SharePoint Server Subscription Edition で 16.0.19725.20384 未満を使用している ・攻撃者が対象 SharePoint Server へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・修正済み更新プログラムが適用されていない ✅悪用時影響 ・SharePoint Server 上でリモートコード実行につながる可能性がある ・SharePoint Server 上の機密情報へ不正アクセスされる可能性がある ・SharePoint Server 上のデータを改ざんされる可能性がある ・SharePoint Server の可用性に影響が生じる可能性がある ・オンプレミス SharePoint 環境を起点に追加侵害へつなげられる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-58644 ・https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644 ・https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-58644.json ・https://github.com/cisagov/vulnrichment/blob/develop/2026/58xxx/CVE-2026-58644.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58644 https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA has added three CVEs to its known‑exploited vulnerabilities catalog, confirming active exploitation. PoC and exploit code are available, detailed technical information and patch links are provided, underscoring the urgency of remediation.

    1502888.3K
    44.2K followersView on X
  • Clandestine@akaclandestine
    Exploit

    CVE-2026-39808 curl -s -k --get "http://$HOST/fortisandbox/job-detail/tracer-behavior" --data-urlencode "jid=|(id &gt; /web/ng/out.txt)|" id #exploit #poc

    Post summary

    A concise curl command demonstrates a functional exploit for CVE‑2026‑39808, evidencing its feasibility and providing a clear proof‑of‑concept for attackers.

    010861.1K
    62.1K followersView on X
  • Zero Hunt@zerohuntai
    Active Exploitation

    FortiSandbox has two unauthenticated command-injection RCEs — CVE-2026-25089 &amp; CVE-2026-39808, CVSS 9.8. Both on CISA KEV, exploited in the wild, federal patch deadline Jul 19. The catch: it's the box your Fortinet fabric asks whether a file is malware. Runbook 🧵 https://t.co/a1Ixtihx8G

    Post summary

    FortiSandbox disclosed two high‑severity unauthenticated command‑injection RCEs (CVE‑2026‑25089 & CVE‑2026‑39808, CVSS 9.8) that are being exploited in the wild, with a federal patch deadline of July 19. No PoC or exploit code is referenced, but a patch is available.

    210531.2K
    15 followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Active Exploitation

    🚨 Upozorňujeme na aktivně zneužívané zranitelnosti ve Fortinet FortiSandbox, CVE-2026-39813, CVE-2026-39808, CVE-2026-25089. Útočníci aktivně zneužívají více chyb ve FortiSandbox, přičemž CVE-2026-39813 (CVSS 9.1) představuje path traversal v JRPC API umožňující neautentizovanému útočníkovi obejít autentizaci prostřednictvím speciálně upravených HTTP požadavků. CVE-2026-39808 (CVSS 9.1) je zranitelnost typu OS command injection, která umožňuje neautentizovanému útočníkovi spouštět neautorizovaný kód či příkazy přes podvržené HTTP požadavky. CVE-2026-25089 (CVSS 9.1) je rovněž OS command injection ovlivňující FortiSandbox, FortiSandbox Cloud a FortiSandbox PaaS WEB UI, která umožňuje spuštění neautorizovaných příkazů bez nutnosti autentizace pomocí speciálně vytvořených HTTP požadavků. Dostupné exploity vykazují znaky generování pomocí AI, nicméně nejsou zatím plně funkční. Všechny zranitelnosti mohou vést k úplnému kompromitování zařízení při vystavení služby síti a nevyžadují předchozí přihlášení, přičemž jejich zneužití bylo pozorováno v reálných útocích během posledních 24 hodin. 📌Doporučujeme FortiSandbox aktualizovat na nejnovější verzi.

    Post summary

    Fortinet FortiSandbox is currently under active exploitation for several high‑severity CVEs, involving path traversal and OS command injection, and users are urged to update immediately.

    030711.2K
    4.3K followersView on X
  • سايبركاست@cyberscastx
    Active Exploitation

    رصد استغلال ثغرتين أمنيتين حرجتين في FortiSandbox في هجمات فعلية، يدفع @CISAgov لإصدار توجيه ملزم بمعالجتهما قبل حلول 19 يوليو الجاري تسمح الثغرتان (CVE-2026-39808) و(CVE-2026-25089) بتنفيذ التعليمات البرمجية عن بعد دون تفاعل المستخدم عبر آليات حقن الأوامر. https://t.co/1m0Y3uczip

    Post summary

    Two critical FortiSandbox CVEs (CVE-2026-39808, CVE-2026-25089) have been actively exploited in real attacks, enabling remote code execution via command injection, which has prompted a CISA directive for remediation before July 19.

    11042624
    6.9K followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    Successful exploitation can enable attackers to run arbitrary commands on vulnerable devices without needing valid credentials. CVE-2026-39808 affects Fortinet FortiSandbox directly. More Details: https://cybersecuritynews.com/fortisandbox-vulnerabilities-exploited/

    Post summary

    The post reports that CVE‑2026‑39808 in Fortinet FortiSandbox has been successfully exploited in the wild, allowing attackers to run arbitrary commands without valid credentials, yet no patch or exploit code is referenced.

    020501.2K
    72.8K followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Patch

    🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik #GüvenlikBülteni Merhaba #Brolyz 🎯 Zafiyet Bilgisi Ürün: #Fortinet #FortiSandbox #Zafiyet: İşletim Sistemi Komut Enjeksiyonu (OS Command Injection) CVE: CVE-2026-39808 Zafiyet Türü: OS Command Injection (CWE-78) Fidye Yazılımı İlişkisi: Şu an için bilinmiyor. 📌 Zafiyet Özeti Fortinet FortiSandbox üzerinde İşletim Sistemi Komut Enjeksiyonu (OS Command Injection) zafiyeti tespit edilmiştir. Bu güvenlik açığı, kimlik doğrulaması gerektirmeyen bir saldırganın özel olarak hazırlanmış HTTP istekleri aracılığıyla cihaz üzerinde yetkisiz kod veya işletim sistemi komutları çalıştırmasına olanak tanıyabilir. Başarılı bir istismar sonucunda saldırgan, FortiSandbox sistemi üzerinde uzaktan kod çalıştırabilir, güvenlik mekanizmalarını devre dışı bırakabilir, hassas verilere erişebilir ve kurumsal ağ içerisinde yatay hareket gerçekleştirerek daha kapsamlı saldırılar düzenleyebilir. 🛡️ Önerilen Aksiyonlar ✅ Güvenlik Güncellemeleri Fortinet tarafından yayımlanan güvenlik güncellemelerini ve önerilen hafifletici önlemleri (Mitigations) test ettikten sonra en kısa sürede canlı ortama uygulayın. ✅ Risk Yönetimi Süreçlerinizi CISA'nın BOD 26-04 (Risk Tabanlı Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Forensics Triage Requirements rehberlerine uygun şekilde yönetin. ✅ Erişim Kontrolleri İnternete açık FortiSandbox sistemlerini öncelikli olarak değerlendirin. Yönetim arayüzlerini yalnızca güvenilir ağlardan erişilebilir hale getirin. IP kısıtlamaları, çok faktörlü kimlik doğrulama (MFA) ve erişim kayıtlarının sürekli izlenmesini sağlayın. ✅ Geçici Koruma Önlemleri Güvenlik güncellemesi veya önerilen hafifletici önlemler uygulanamıyorsa, FortiSandbox yönetim arayüzünün internet erişimini geçici olarak kapatın veya yalnızca VPN üzerinden erişilebilir hale getirin. 📚 Referans: Fortinet Security Advisories & CISA

    Post summary

    Fortinet FortiSandbox suffers a confirmed OS Command Injection (CVE-2026-39808) that lets unauthenticated attackers run arbitrary code.  Applying the vendor security patch and mitigations, or temporarily blocking internet access, are recommended defensive actions.

    0105056
    530 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-39808 - critical 🚨 Fortinet FortiSandbox - Command Injection &gt; Fortinet FortiSandbox 4.4.0 through 4.4.8 contains a command injection caused by impr... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-39808 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet discloses CVE-2026-39808, a critical command injection vulnerability in Fortinet FortiSandbox versions 4.4.0‑4.4.8, and points to a Project Discovery library page for additional details.

    01022191
    942 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortisandbox---

Explore more