Web_Logo
Remote Support
Security Alert: Fortinet FortiSandbox Vulnerabilities Under Active Attack
Home » Security Alerts  »  Security Alert: Fortinet FortiSandbox Vulnerabilities Under Active Attack

Security Alert: Fortinet FortiSandbox Vulnerabilities Under Active Attack

Three critical vulnerabilities in Fortinet FortiSandbox are being actively exploited by attackers as of June 16, 2026. Businesses running Fortinet network security appliances should treat this as urgent and apply available patches immediately.

  • What it is: Three vulnerabilities (CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089) in Fortinet FortiSandbox. The most severe, CVE-2026-25089 (CVSS 9.1), allows an unauthenticated attacker to execute arbitrary system commands remotely — no login required.
  • Who is affected: Any organisation running Fortinet FortiSandbox on-premises or in a hybrid environment. Internet-facing deployments are at the highest risk because no authentication is required to trigger the exploit.
  • What the risk is: Successful exploitation can give attackers full control over the affected appliance, with potential to move laterally into your broader network. Live attack telemetry from security researchers confirms exploitation attempts are actively underway.
  • What to do: Apply Fortinet's available patches immediately. If patching cannot happen right away, restrict access to the management interface and block public access to port 443 on the device where operationally possible.

We recommend contacting your IT provider today if you are running Fortinet FortiSandbox in your environment. Sources: Help Net Security, BleepingComputer.