๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability
Summary
Fortinet FortiSandbox has a vulnerability that allows attackers without authentication to run unauthorized commands on the system through specially crafted HTTP requests (OS command injection, where an attacker tricks the system into executing their commands). This vulnerability is actively being exploited by real attackers. Organizations must apply fixes according to vendor instructions and follow CISA's BOD 26-04 guidance on prioritizing security updates, with a deadline of July 19, 2026.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Vulnerability Details
EPSS: 48.7%
Yes
๐ฅ Actively Exploited
July 15, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-39808
First tracked: July 16, 2026 at 02:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%