Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April
Vulnerability: Attackers exploit FortiSandbox vulnerabilities (CVE-2026-39808 and CVE-2026-39813) for command injection and path traversal, risking enterprise security.
Deep Analysis and Expert Commentary
The exploitation of these FortiSandbox vulnerabilities highlights a critical attack vector in enterprise security. Attackers leverage CVE-2026-39808 (OS-command injection) and CVE-2026-39813 (path-traversal) to bypass authentication and execute arbitrary commands, potentially gaining elevated access. The widespread exploitation attempts, originating from multiple countries, suggest a coordinated effort rather than isolated incidents. FortiSandbox's role in analyzing suspicious content makes it a high-value target, as compromise could undermine broader detection workflows. Mitigations include immediate patching, network segmentation, and monitoring for unusual activity. The lack of CISA inclusion in the known exploited vulnerabilities catalog underscores the need for proactive defense measures.
Action Items
- Patch FortiSandbox appliances immediately to address CVE-2026-39808 and CVE-2026-39813.
- Segment networks to limit lateral movement in case of compromise.
- Monitor for unusual activity, especially from the identified IPs and countries.
Original Article Brief Intro
CyberScoop · 2026-06-17 · Vulnerability: Attackers exploit FortiSandbox vulnerabilities (CVE-2026-39808 and CVE-2026-39813) for command injection and path traversal, risking enterprise security.
Related Terms and Notes
CVE IDs
- CVE-2026-39808 — OS-command injection vulnerability in FortiSandbox allowing arbitrary command execution.
- CVE-2026-39813 — Path-traversal vulnerability in FortiSandbox enabling unauthorized file access.
Techniques / TTPs
- RCE
Context Notes
- Command Injection
- FortiSandbox
- Path-Traversal