← Back to Feed
Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-39808
July 31, 2026 · CISA · Severity: CRITICAL
Fortinet FortiSandbox: Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Vendor: Fortinet
Product: FortiSandbox
CISA Date Added: 2026-07-16
CVE: CVE-2026-39808
This vulnerability is actively exploited in the wild according to CISA Known Exploited Vulnerabilities catalog.
Key Takeaways
- CVE-2026-39808 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
- The vulnerability allows SQL injection attacks, which can lead to data theft, authentication bypass, or remote code execution.
- CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
- Fortinet FortiSandbox: Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.