Two critical security flaws in Fortinet's FortiSandbox product are being actively exploited by attackers, and the US Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch them immediately.
- What it is: Two vulnerabilities (CVE-2026-39808 and CVE-2026-25089) allow an attacker to send a specially crafted request to a FortiSandbox device and run commands on it without needing a username or password.
- Who is affected: Businesses running FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS as part of their network security setup.
- The risk: Both flaws carry a near-maximum severity score, and CISA has confirmed they are already being used in real attacks.
- What action is needed: Fortinet released fixes for these issues earlier this year, in April and June. If your FortiSandbox appliance hasn't been patched since then, treat this as urgent.
If you're unsure whether your Fortinet devices are up to date, we recommend checking with your IT provider this week rather than waiting for the next scheduled maintenance window.