Critical Fortinet FortiSandbox Flaws Exploited in Attacks
Key Takeaways Multiple critical vulnerabilities in Fortinet’s FortiSandbox platform are currently being actively exploited by threat actors. Three specific CVEs (CVE-2026-39813, CVE-2026-39808,...
Key Takeaways
- Multiple critical vulnerabilities in Fortinet’s FortiSandbox platform are currently being actively exploited by threat actors.
- Three specific CVEs (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are under attack, with one (CVE-2026-39813) seeing its first-ever recorded exploitation.
- The vulnerabilities allow unauthenticated remote attackers to bypass authentication, execute arbitrary commands as root, and access sensitive system data.
- Fortinet has released patches; users should update to versions 4.4.9, 5.0.6+, or later to mitigate risks.
Active Exploitation Targets Fortinet FortiSandbox
Threat actors are actively leveraging several critical vulnerabilities within Fortinet’s FortiSandbox platform, with live attack telemetry confirming exploitation attempts over the last 24 hours. The cybersecurity firm Defused has identified three specific CVEs as targets in these ongoing campaigns.
Table Of Content
Honeypot sensors and deception infrastructure, configured to mimic Fortinet FortiSandbox instances, have captured these exploitation attempts. All observed attacks were initiated over port 443 through specially crafted POST requests directed at the /jsonrpc/ API endpoint.
Details of Exploited Vulnerabilities
- CVE-2026-39813: Path Traversal in JRPC API
This vulnerability, a path traversal flaw (CWE-24) within the FortiSandbox JRPC API, permits an unauthenticated remote attacker to bypass authentication. Attackers achieve this by sending specially crafted HTTP requests. By injecting traversal sequences, such assession: "../../tmp/", into the API, they can access sensitive system information including configuration backups, serial numbers, and version details without requiring any credentials. This cluster of attacks marks the first recorded instance of in-the-wild exploitation for CVE-2026-39813. - CVE-2026-39808: OS Command Injection
An OS command injection vulnerability (CWE-78) in a FortiSandbox API endpoint allows unauthenticated attackers to execute arbitrary commands with root privileges. A public proof-of-concept (PoC) exploit for this flaw has been available since April 2026, which weaponizes thejidGET parameter via pipe-chained Unix commands. Payloads consistent with this publicly available PoC are now being observed in live exploitation attempts. - CVE-2026-25089: Second OS Command Injection
This is another OS command injection vulnerability (CWE-78) affecting the FortiSandbox Web UI. It impacts versions 5.0.0–5.0.5, 4.4.0–4.4.8, all 4.2 versions, and FortiSandbox Cloud/PaaS deployments. Notably, no functional public exploit has been disclosed for this specific CVE. Despite the lack of a public exploit, observed exploitation attempts suggest “vibecoded” attacks—likely AI-assisted or heuristically generated exploits with potentially faulty logic—indicating opportunistic actors are probing for weaknesses without a fully validated payload.
All three CVEs can be triggered without prior authentication using a single HTTP request. This means that any exposed FortiSandbox management interface is vulnerable to exploitation without requiring existing access or credentials.
A successful compromise of a FortiSandbox instance could enable threat actors to approve malicious files as legitimate to dependent Fortinet products or establish a pivot point for lateral movement within an affected enterprise network.
The IP address 141.11.43[.]175 has been identified as an attacker source in active exploitation. This IP is attributed to AS136510 Streamline Servers Pty Ltd (Singapore) and is flagged with a high-interest threat score.
Affected Versions
Organizations using FortiSandbox are advised to review the following affected versions and apply necessary updates:
| CVE | Affected Versions | Fixed Version |
|---|---|---|
| CVE-2026-39813 | FortiSandbox 4.4.0–4.4.8, 5.0.0–5.0.5 | 4.4.9, 5.0.6+ |
| CVE-2026-39808 | FortiSandbox 4.4.0–4.4.8 | 4.4.9+ |
| CVE-2026-25089 | FortiSandbox 4.2 all versions, 4.4.0–4.4.8, 5.0.0–5.0.5; Cloud/PaaS 5.0.4–5.0.5 | 4.4.9, 5.0.6+ |
Indicators of Compromise (IOCs)
Organizations should monitor for the following indicators:
| Type | Value | Context |
|---|---|---|
| Attacker IP | 141.11.43.175 |
Observed exploit source |
| ASN | AS136510 | Streamline Servers Pty Ltd, SG |
| Target Port | 443 | HTTPS/JRPC API |
| Target Endpoint | /jsonrpc/ |
FortiSandbox API path |
| User-Agent | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 |
Observed in live requests |
What You Should Do
- Patch Immediately: Update all affected FortiSandbox instances to the fixed versions (4.4.9, 5.0.6+, or later) as soon as possible.
- Review Network Exposure: Ensure that FortiSandbox management interfaces are not directly exposed to the internet. Implement strict network segmentation and access controls.
- Monitor for IOCs: Actively monitor network traffic and logs for the provided Indicators of Compromise (IOCs), including the attacker IP address, ASN, target port, and API endpoint.
- Audit System Logs: Check FortiSandbox logs for any suspicious activity, especially attempts to access sensitive data or execute commands via the
/jsonrpc/API endpoint. - Isolate and Investigate: If compromise is suspected, isolate affected systems and conduct a thorough forensic investigation.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.