CVE-2026-39813Active Exploitation(fortinet / fortisandbox)

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 13 mentions and remains active

Immediate actions

  • Patch fortinet fortisandbox systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-24

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortisandbox

Threat summary

  • Active exploitation appears in 30 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 66 mentions across 24 observed days

What's happening

  • Active exploitation reported across 30 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 33 signals
  • Technical details provided in 40 signals
  • Disclosure: 10 classified signals
  • Peaked 12d ago at 13 mentions (2026-06-16); latest day: 1
  • 66 total mentions across 24 days

Affected systems

Vendors
Products
fortisandbox

Deep dive

Activity timeline66 mentions / 24d
0371013Mentions · 2026-04-14: 4Mentions · 2026-04-15: 6Mentions · 2026-04-16: 8Mentions · 2026-04-17: 3Mentions · 2026-04-18: 1Mentions · 2026-04-19: 1Mentions · 2026-04-20: 2Mentions · 2026-04-21: 2Mentions · 2026-04-22: 2Mentions · 2026-04-23: 1Mentions · 2026-06-15: 1Mentions · 2026-06-16: 13Mentions · 2026-06-17: 9Mentions · 2026-06-18: 2Mentions · 2026-06-23: 1Mentions · 2026-06-26: 1Mentions · 2026-06-27: 2Mentions · 2026-06-29: 1Mentions · 2026-06-30: 1Mentions · 2026-07-01: 1Mentions · 2026-07-16: 1Mentions · 2026-07-17: 1Mentions · 2026-08-16: 1Mentions · 2026-09-01: 1PoC Mentioned / Linked · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-21: 1PoC Mentioned / Linked · 2026-04-22: 1PoC Mentioned / Linked · 2026-04-23: 1PoC Mentioned / Linked · 2026-06-16: 2Exploit Tool / Code · 2026-06-16: 1Active Exploitation · 2026-04-21: 1Active Exploitation · 2026-06-15: 1Active Exploitation · 2026-06-16: 12Active Exploitation · 2026-06-17: 9Active Exploitation · 2026-06-18: 2Active Exploitation · 2026-06-23: 1Active Exploitation · 2026-06-27: 1Active Exploitation · 2026-07-16: 1Active Exploitation · 2026-07-17: 1Active Exploitation · 2026-08-16: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-15: 4Patch / Workaround · 2026-04-16: 7Patch / Workaround · 2026-04-17: 2Patch / Workaround · 2026-04-18: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-06-16: 6Patch / Workaround · 2026-06-17: 3Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-27: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-07-17: 1Patch / Workaround · 2026-08-16: 1Technical Details · 2026-04-14: 4Technical Details · 2026-04-15: 5Technical Details · 2026-04-16: 3Technical Details · 2026-04-17: 1Technical Details · 2026-04-18: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 1Technical Details · 2026-06-16: 8Technical Details · 2026-06-17: 4Technical Details · 2026-06-18: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-29: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-16: 1Technical Details · 2026-07-17: 1Technical Details · 2026-08-16: 1Technical Details · 2026-09-01: 104-1404-1604-1804-2004-2206-1506-1706-2306-2706-3007-1608-1609-01
Signal classification5 categories
Active Exploitation
2943.9%
Patch
1928.8%
Disclosure
1015.2%
General
69.1%
PoC
23.0%
Referenced assets57 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-144
Disclosure4
2026-04-156
Disclosure1General1Patch4
2026-04-168
Disclosure1Patch7
2026-04-173
General1Patch2
2026-04-181
Patch1
2026-04-191
Disclosure1
2026-04-202
General1Patch1
2026-04-212
Disclosure1Patch1
2026-04-222
General1PoC1
2026-04-231
PoC1
2026-06-151
Active Exploitation1
2026-06-1613
Active Exploitation12Patch1
2026-06-179
Active Exploitation9
2026-06-182
Active Exploitation2
2026-06-231
Active Exploitation1
2026-06-261
General1
2026-06-272
Active Exploitation1Disclosure1
2026-06-291
Disclosure1
2026-06-301
Patch1
2026-07-011
Patch1
2026-07-161
Active Exploitation1
2026-07-171
Active Exploitation1
2026-08-161
Active Exploitation1
2026-09-011
General1
Full discourse20 posts
  • Rishi@rxerium
    Disclosure

    🚨 Fortinet just disclosed CVE-2026-39808 and CVE-2026-39813 - 2 critical vulnerabilities affecting FortiSandbox. No active exploitation itw reported as of yet. Scan your infrastructure to find vulnerable instances: CVE-2026-39808: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-39808.yaml CVE-2026-39813: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-39813.yaml CVE-2026-39808 (CVSS 9.1): An Improper Neutralization of Special Elements used in an OS Command ('OS command injection') vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. CVE-2026-39813 (CVSS 9.1): A Path Traversal vulnerability [CWE-24] in FortiSandbox JRPC API may allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests. Patches are available as per vendor advisories: https://fortiguard.fortinet.com/psirt/FG-IR-26-112 https://fortiguard.fortinet.com/psirt/FG-IR-26-100

    Post summary

    Fortinet disclosed two critical FortiSandbox vulnerabilities (CVE-2026-39808 and CVE-2026-39813), providing PoC templates and patch links while noting that no exploitation has been reported yet.

    269628313547.5K
    3.8K followersView on X
  • Morty@MortyJin
    PoC

    CVE-2026-39813 (CVSS 9.1): A path traversal in FortiSandbox's JRPC API allows unauthenticated access to system info, configs, and encrypted backups — no credentials needed. Full technical write-up with bytecode-level analysis: https://rustlang.rs/posts/blog_cve_2026_39813_en/ https://t.co/JAuU5X69ro

    Post summary

    The post announces CVE-2026-39813, describing a path‑traversal exploit in FortiSandbox with high severity, and links to a technical write‑up that likely includes PoC code.

    03201456212.3K
    163 followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨We are observing exploitation of multiple Fortinet FortiSandbox vulnerabilities during the past 24 hours, including: CVE-2026-39813 (no previous recorded exploitation) CVE-2026-39808 CVE-2026-25089 (vibecoded, likely faulty exploit) Per our research a working exploit for CVE-2026-25089 has not yet been publicly disclosed. Track FortiSandbox exploitation 👉 https://console.defusedcyber.com/signup

    Post summary

    The post reports active exploitation of several Fortinet FortiSandbox CVEs in the past 24 hours, with no public PoC, exploit tool, or patch disclosed.

    217254166.9K
    7.6K followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-39808 & CVE-2026-39813 : 2 critical vulnerabilities affecting FortiSandbox. 📊 203 Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22FortiSandbox%22 👇Query HUNTER : http://product.name="FortiSandbox" 📰Refer:https://securityonline.info/fortinet-fortisandbox-critical-vulnerability-cve-2026-39813-cve-2026-39808/ https://fortiguard.fortinet.com/psirt/FG-IR-26-100 https://fortiguard.fortinet.com/psirt/FG-IR-26-112 #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The tweet announces the discovery of two critical vulnerabilities (CVE‑2026‑39808 and CVE‑2026‑39813) affecting FortiSandbox, providing links to informational sources and vendor PSIRT pages but no technical or exploit details.

    02103883.3K
    25.9K followersView on X
  • Cloudflare Changelog@CFchangelog
    Patch

    WAF Release 2026-07-01 blocks a Fortinet path traversal flaw and disables the Fake Bing bot rule. Patch CVE-2026-39813 and clean up your blocking logic. https://developers.cloudflare.com/changelog/post/2026-07-01-waf-release/

    Post summary

    Cloudflare announced a WAF release that includes blocking for the Fortinet path traversal flaw (CVE-2026-39813) and urges users to apply the patch and review blocking logic.

    0201831.8K
    5.1K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Active Exploitation

    🚨 Upozorňujeme na aktivně zneužívané zranitelnosti ve Fortinet FortiSandbox, CVE-2026-39813, CVE-2026-39808, CVE-2026-25089. Útočníci aktivně zneužívají více chyb ve FortiSandbox, přičemž CVE-2026-39813 (CVSS 9.1) představuje path traversal v JRPC API umožňující neautentizovanému útočníkovi obejít autentizaci prostřednictvím speciálně upravených HTTP požadavků. CVE-2026-39808 (CVSS 9.1) je zranitelnost typu OS command injection, která umožňuje neautentizovanému útočníkovi spouštět neautorizovaný kód či příkazy přes podvržené HTTP požadavky. CVE-2026-25089 (CVSS 9.1) je rovněž OS command injection ovlivňující FortiSandbox, FortiSandbox Cloud a FortiSandbox PaaS WEB UI, která umožňuje spuštění neautorizovaných příkazů bez nutnosti autentizace pomocí speciálně vytvořených HTTP požadavků. Dostupné exploity vykazují znaky generování pomocí AI, nicméně nejsou zatím plně funkční. Všechny zranitelnosti mohou vést k úplnému kompromitování zařízení při vystavení služby síti a nevyžadují předchozí přihlášení, přičemž jejich zneužití bylo pozorováno v reálných útocích během posledních 24 hodin. 📌Doporučujeme FortiSandbox aktualizovat na nejnovější verzi.

    Post summary

    Fortinet’s FortiSandbox vulnerabilities (CVE‑2026‑39813, CVE‑2026‑39808, CVE‑2026‑25089) are actively exploited via crafted HTTP requests, with both path traversal and OS command injection issues scored at CVSS 9.1. Immediate patching is recommended and the exploits are still incomplete, but real-world attacks have been observed in the last 24 hours.

    030711.2K
    4.3K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    【今日のForti】FortiSandboxで重大(Critical)な脆弱性2件が修正。CVE-2026-39813及びCVE-2026-39808。それぞれ認証迂回と無認証での任意コード実行。社内発見。修正版提供済み。 https://www.helpnetsecurity.com/2026/04/16/fortinet-fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808/

    Post summary

    FortiSandbox's two critical vulnerabilities—auth‑bypass (CVE‑2026‑39813) and unauthenticated arbitrary code execution (CVE‑2026‑39808)—were internally discovered and patched, with the fixes already distributed.

    110211.6K
    7.6K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    ぱっちちゅーずでー ◆ Microsoft 2026 年 4 月のセキュリティ更新プログラム (月例) https://www.microsoft.com/en-us/msrc/blog/2026/04/202604-security-update CVE-2026-33825 Microsoft Defender の特権の昇格の脆弱性 CVE-2026-32201 Microsoft SharePoint Server のなりすましの脆弱性 ◆Fortinet https://fortiguard.fortinet.com/psirt ・FG-IR-26-100 / CVE-2026-39808 FortiSandbox 4.4系のAPIにある OSコマンドインジェクション。細工したリクエストを受けると、認証なしで任意コードや任意コマンドを実行される恐れがあります。外部公開や到達可能性がある環境では、優先度高めでの確認が必要です。 ・FG-IR-26-112 / CVE-2026-39813 FortiSandbox のJRPC APIにある パストラバーサル起因の認証回避・権限昇格。特別に細工したHTTPリクエストで未認証のまま認証をバイパスし、権限を引き上げられる可能性があるため、管理API露出環境では特に注意が必要です。 ・FG-IR-26-121 / CVE-2026-22828 FortiAnalyzer Cloud / FortiManager Cloud の oftpd にある ヒープベースのバッファオーバーフロー。細工したリクエストにより、リモートの未認証攻撃者が任意コードやコマンド実行に至る可能性がありますが、悪用にはASLRや分離構成を踏まえた準備が必要です。 ◆Ivanti https://www.ivanti.com/blog/april-2026-security-update https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-4913-CVE-2026-4… ◆Adobe(Criticalで任意のコード実行のみ抽出) https://helpx.adobe.com/security.html ・Adobe ColdFusion(APSB26-38) CVE-2026-27304, CVE-2026-27306 入力検証不備により、任意のコード実行につながる脆弱性 ・Adobe Connect(APSB26-37) CVE: CVE-2026-27302, CVE-2026-27303, CVE-2026-27243, CVE-2026-27245, CVE-2026-27246, CVE-2026-34615 デシリアライズ不備や XSS を起点に、任意のコード実行が可能となる脆弱性 ・Adobe FrameMaker(APSB26-36) CVE: CVE-2026-27290, CVE-2026-27292, CVE-2026-27293, CVE-2026-27294, CVE-2026-27295, CVE-2026-27296, CVE-2026-27297, CVE-2026-27298 任意のコード実行につながる脆弱性群 ・Adobe Bridge(APSB26-39) CVE: CVE-2026-34630, CVE-2026-27310, CVE-2026-27311, CVE-2026-27312, CVE-2026-27313 複数のヒープベース・バッファオーバーフローにより、任意のコード実行が可能になる脆弱性 ・Adobe Photoshop(APSB26-40) CVE: CVE-2026-27289 境界外読み取りにより、任意のコード実行につながる脆弱性 ・Adobe Illustrator(APSB26-42) CVE: CVE-2026-34618 境界外書き込みにより、任意のコード実行につながる脆弱性 ◆SAP SAP Security Patch Day - April 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/april-2026.html CVE-2026-27681 https://www.cve.org/CVERecord?id=CVE-2026-27681 『(直訳)SAP Business Planning and ConsolidationおよびSAP Business Warehouseにおける認証チェックの不備により、認証済みのユーザーが細工されたSQL文を実行してデータベースデータを読み取り、変更、削除できる脆弱性が存在します。これは、システムの機密性、完全性、可用性に重大な影響を及ぼします。』

    Post summary

    The message aggregates April 2026 security advisories for multiple vendors, listing CVEs with technical details and links to corporate advisory pages, but it does not mention PoC code, active exploitation, or patch specifics.

    000321.4K
    11.7K followersView on X
  • سايبركاست@cyberscastx
    General

    تحذير عاجل من @Fortinet بشأن ثغرات حرجة في FortiSandbox تستهدف الثغرتان واجهات برمجة التطبيقات لمنصة FortiSandbox عبر طلبات HTTP مصممة خصيصاً. تتيح الثغرة الأولى CVE-2026-39813، تجاوز المصادقة وتصعيد الصلاحيات، بينما تسمح الثانية CVE-2026-39808 بتنفيذ أوامر على نظام التشغيل. https://t.co/Z2EcroPGmj

    Post summary

    Fortinet issues an urgent warning about two critical FortiSandbox APIs – CVE‑2026‑39813 (auth bypass/priv‑elev) and CVE‑2026‑39808 (OS command execution) – but provides no PoC, exploit code, or mitigation details.

    10030559
    6.8K followersView on X
  • dbugs@ptdbugs
    PoC

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-39813 PT ID: PT-2026-32692 Vendor: Fortinet Product: FortiSandbox Description: A path traversal vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8 may allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests. Link: https://rustlang.rs/posts/blog_cve_2026_39813_en/ #dbugs_vuln

    Post summary

    A PoC for CVE-2026-39813, a path‑traversal flaw in FortiSandbox, has been disclosed via a blog link, but no active exploitation or patch information is provided.

    01020153
    798 followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: Critical #FortiSandbox #vulnerabilities leading to Remote Code Execution #RCE. #CVE-2026-39813 & #CVE-2026-39808 CVSS: 9.8 are now actively exploited in the wild. Read our updated advisory at https://ccb.belgium.be/advisories/warning-remote-code-execution-privilege-escalation-fortinet-fortisandbox-patch and #Patch #Patch #Patch

    Post summary

    FortiSandbox CVEs 2026-39813 and 2026-39808, each with CVSS 9.8, are being actively exploited; a patch advisory is publicly available.

    01100461
    7.2K followersView on X
  • Tre B@trerbbb
    Patch

    if you run fortinet, patch tonight. CVE-2026-39813 weaponized, CVSS high. workaround: block external access to the affected endpoint until patched. #Fortinet #PatchTuesday #PathTraversal #CVE-2026-39813 https://valtikstudios.com/blog

    Post summary

    Fortinet CVE-2026-39813 is a high‑severity, weaponized path traversal vulnerability; operators are advised to block external access to affected endpoints until a patch is applied.

    0101060
    17 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Fortinet ❗ CVE-2026-39815 ❗ CVE-2026-39813 ❗ CVE-2026-39808 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-fortinet-10/ https://t.co/eCsaTqaIiG

    Post summary

    Fortinet products are reported to have multiple CVEs, with references to external links for details; the post lacks direct evidence of PoC, exploit tools, active exploitation, or mitigation steps.

    00011270
    6.7K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    FortiSandbox: 3 CVEs exploited Three FortiSandbox flaws under active exploitation, all already patched: •CVE-2026-39813 (9.1) auth bypass •CVE-2026-39808 (9.1) OS command injection •CVE-2026-25089 (9.1) unauth command execution (Web UI) It feeds verdicts to your whole Fortinet stack. Patch to 5.0.6 / 4.4.9+ and lock the Web UI to trusted IPs. Source: @SecurityWeek @VulnerabilityNews

    Post summary

    The post reports that three FortiSandbox vulnerabilities are actively being exploited in the wild, provides patch versions and mitigation steps, and details the types of exploits involved.

    0101088
    184 followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    Attackers are exploiting FortiSandbox vulnerabilities https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet reports that FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are being actively exploited by attackers. No PoC, exploit tool, patch, or technical details are referenced.

    00020346
    194.7K followersView on X
  • Clone Systems@CloneSystemsInc
    Active Exploitation

    CVE Alert: Fortinet FortiSandbox Attackers are reportedly exploiting three Fortinet FortiSandbox vulnerabilities: • CVE-2026-39813 | CVSS 9.1 • CVE-2026-39808 | CVSS 9.1 • CVE-2026-25089 | CVSS 9.1 The flaws include path traversal and OS command injection issues that could allow unauthenticated attackers to bypass authentication or execute unauthorized commands through crafted HTTP requests. Two of the vulnerabilities were patched in April 2026, while CVE-2026-25089 was patched last week. Organizations using FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS should apply the latest Fortinet updates immediately, review exposure, and monitor for suspicious activity. Critical appliance vulnerabilities continue to be heavily targeted. Patch quickly and validate remediation. #Cybersecurity #CVEAlert #Fortinet #FortiSandbox #VulnerabilityManagement #ThreatIntelligence #PatchManagement #NetworkSecurity #CloneSystems

    Post summary

    Three Fortinet FortiSandbox CVEs (CVE‑2026‑39813, CVE‑2026‑39808, CVE‑2026‑25089) are being actively exploited via path traversal and OS command injection. All have been patched, and users should immediately apply the latest updates to mitigate the risk.

    0002074
    258 followersView on X
  • dbugs@ptdbugs
    Disclosure

    CVE: CVE-2026-39813 PT ID: PT-2026-32692 Vendor: Fortinet Product: FortiSandbox CVSS: 9.1 Credits: n/a Description: A path traversal vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8 may allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-39813 • https://fortiguard.fortinet.com/psirt/FG-IR-26-112 #dbugs_vuln

    Post summary

    The text is a standard vulnerability disclosure for FortiSandbox, detailing a path traversal flaw enabling authentication bypass, without any PoC, exploit, or patch information.

    00020158
    2.3K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-33829 2 - CVE-2026-33826 3 - CVE-2026-39813 4 - CVE-2026-30898 5 - CVE-2026-4631 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five CVE identifiers as trending with no additional details or context.

    00011172
    1.7K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical Path Traversal and OS Command Injection in #FortiSandbox. #CVE-2026-39813 & #CVE-2026-39808 CVSS: 9.8. These flaws can lead to privilege escalation and remote code execution. https://ccb.belgium.be/advisories/warning-remote-code-execution-privilege-escalation-fortinet-fortisandbox-patch #Patch #Patch #Patch

    Post summary

    The advisory highlights critical CVEs in FortiSandbox with details on traversal and OS command injection that could lead to remote code execution, and it indicates that patches are available.

    01010263
    7.2K followersView on X
  • Emphere@empherehq
    Active Exploitation

    FortiSandbox has two command-injection CVEs in CISA KEV as of 2026-07-16: CVE-2026-39808 and CVE-2026-25089. The due date is 2026-07-19. But exploitation was reported in mid-June. That leaves roughly a month between confirmed in-the-wild activity and the formal signal many patch SLAs use to start the clock. The third patched FortiSandbox issue, CVE-2026-39813, is the auth-bypass piece of the chain and is not on KEV. For systems that issue threat verdicts to the rest of the stack, KEV timing is not a proxy for risk timing.

    Post summary

    FortiSandbox’s command‑injection CVEs were actively exploited in mid‑June, with KEV due dates set for July 2026 and a patch schedule already outlined.

    1000086
    7 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortisandbox---

Explore more