Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Mozilla Revokes Firefox Signing Key After GitHub Exposure of Subkey
August 11, 2026
Critical Vulnerability in Emerson Controllers Lets Attackers Spoof Temperatures
August 11, 2026
US SOCs Combat Alert Fatigue: Strategies for Cybersecurity Noise Reduction
August 11, 2026
Home/CyberSecurity News/Critical Fortinet FortiSandbox Flaws Exploited in Attacks
CyberSecurity News

Critical Fortinet FortiSandbox Flaws Exploited in Attacks

Key Takeaways Multiple critical vulnerabilities in Fortinet’s FortiSandbox platform are currently being actively exploited by threat actors. Three specific CVEs (CVE-2026-39813, CVE-2026-39808,...

Marcus Rodriguez
Marcus Rodriguez
June 16, 2026 3 Min Read
44 0

Key Takeaways

  • Multiple critical vulnerabilities in Fortinet’s FortiSandbox platform are currently being actively exploited by threat actors.
  • Three specific CVEs (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are under attack, with one (CVE-2026-39813) seeing its first-ever recorded exploitation.
  • The vulnerabilities allow unauthenticated remote attackers to bypass authentication, execute arbitrary commands as root, and access sensitive system data.
  • Fortinet has released patches; users should update to versions 4.4.9, 5.0.6+, or later to mitigate risks.

Active Exploitation Targets Fortinet FortiSandbox

Threat actors are actively leveraging several critical vulnerabilities within Fortinet’s FortiSandbox platform, with live attack telemetry confirming exploitation attempts over the last 24 hours. The cybersecurity firm Defused has identified three specific CVEs as targets in these ongoing campaigns.

Table Of Content

  • Key Takeaways
  • Active Exploitation Targets Fortinet FortiSandbox
  • Details of Exploited Vulnerabilities
  • Affected Versions
  • Indicators of Compromise (IOCs)
  • What You Should Do

Honeypot sensors and deception infrastructure, configured to mimic Fortinet FortiSandbox instances, have captured these exploitation attempts. All observed attacks were initiated over port 443 through specially crafted POST requests directed at the /jsonrpc/ API endpoint.

Details of Exploited Vulnerabilities

  • CVE-2026-39813: Path Traversal in JRPC API
    This vulnerability, a path traversal flaw (CWE-24) within the FortiSandbox JRPC API, permits an unauthenticated remote attacker to bypass authentication. Attackers achieve this by sending specially crafted HTTP requests. By injecting traversal sequences, such as session: "../../tmp/", into the API, they can access sensitive system information including configuration backups, serial numbers, and version details without requiring any credentials. This cluster of attacks marks the first recorded instance of in-the-wild exploitation for CVE-2026-39813.
  • CVE-2026-39808: OS Command Injection
    An OS command injection vulnerability (CWE-78) in a FortiSandbox API endpoint allows unauthenticated attackers to execute arbitrary commands with root privileges. A public proof-of-concept (PoC) exploit for this flaw has been available since April 2026, which weaponizes the jid GET parameter via pipe-chained Unix commands. Payloads consistent with this publicly available PoC are now being observed in live exploitation attempts.
  • CVE-2026-25089: Second OS Command Injection
    This is another OS command injection vulnerability (CWE-78) affecting the FortiSandbox Web UI. It impacts versions 5.0.0–5.0.5, 4.4.0–4.4.8, all 4.2 versions, and FortiSandbox Cloud/PaaS deployments. Notably, no functional public exploit has been disclosed for this specific CVE. Despite the lack of a public exploit, observed exploitation attempts suggest “vibecoded” attacks—likely AI-assisted or heuristically generated exploits with potentially faulty logic—indicating opportunistic actors are probing for weaknesses without a fully validated payload.

All three CVEs can be triggered without prior authentication using a single HTTP request. This means that any exposed FortiSandbox management interface is vulnerable to exploitation without requiring existing access or credentials.

A successful compromise of a FortiSandbox instance could enable threat actors to approve malicious files as legitimate to dependent Fortinet products or establish a pivot point for lateral movement within an affected enterprise network.

The IP address 141.11.43[.]175 has been identified as an attacker source in active exploitation. This IP is attributed to AS136510 Streamline Servers Pty Ltd (Singapore) and is flagged with a high-interest threat score.

Affected Versions

Organizations using FortiSandbox are advised to review the following affected versions and apply necessary updates:

CVE Affected Versions Fixed Version
CVE-2026-39813 FortiSandbox 4.4.0–4.4.8, 5.0.0–5.0.5 4.4.9, 5.0.6+
CVE-2026-39808 FortiSandbox 4.4.0–4.4.8 4.4.9+
CVE-2026-25089 FortiSandbox 4.2 all versions, 4.4.0–4.4.8, 5.0.0–5.0.5; Cloud/PaaS 5.0.4–5.0.5 4.4.9, 5.0.6+

Indicators of Compromise (IOCs)

Organizations should monitor for the following indicators:

Type Value Context
Attacker IP 141.11.43.175 Observed exploit source
ASN AS136510 Streamline Servers Pty Ltd, SG
Target Port 443 HTTPS/JRPC API
Target Endpoint /jsonrpc/ FortiSandbox API path
User-Agent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Observed in live requests

What You Should Do

  • Patch Immediately: Update all affected FortiSandbox instances to the fixed versions (4.4.9, 5.0.6+, or later) as soon as possible.
  • Review Network Exposure: Ensure that FortiSandbox management interfaces are not directly exposed to the internet. Implement strict network segmentation and access controls.
  • Monitor for IOCs: Actively monitor network traffic and logs for the provided Indicators of Compromise (IOCs), including the attacker IP address, ASN, target port, and API endpoint.
  • Audit System Logs: Check FortiSandbox logs for any suspicious activity, especially attempts to access sensitive data or execute commands via the /jsonrpc/ API endpoint.
  • Isolate and Investigate: If compromise is suspected, isolate affected systems and conduct a thorough forensic investigation.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Threat Intelligence: When Do IOCs Expire and Stop Being Useful

Next Post

Ghostwriter Hackers Abuse Gmail Admin Emails to Steal Credentials, 2FA

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical FortiGate RCE CVE-2022-42475 Exploited in Polish Energy Sector Attack
August 11, 2026
GhostJacking Attack Hijacks AI Agents to Run Malicious Code on Developer Machines
August 11, 2026
Horizon3.ai Secures $20M to Boost Partner-Led Growth and Ecosystem
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us