← Back to Feed

Fortinet FortiSandbox OS Command Injection Vulnerability

CVE-2026-39808

July 31, 2026 · CISA · Severity: CRITICAL

Fortinet FortiSandbox: Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. Vendor: Fortinet Product: FortiSandbox CISA Date Added: 2026-07-16 CVE: CVE-2026-39808 This vulnerability is actively exploited in the wild according to CISA Known Exploited Vulnerabilities catalog.

Key Takeaways

  • CVE-2026-39808 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
  • The vulnerability allows SQL injection attacks, which can lead to data theft, authentication bypass, or remote code execution.
  • CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
  • Fortinet FortiSandbox: Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
☕ Buy a Coffee