XOOMAR
Three glowing cyber bugs breach shielded sandbox servers in a dark security operations environment.
CybersecurityJune 17, 2026· 5 min read· By XOOMAR Insights Team

Hackers Pounce on Fortinet FortiSandbox Bugs After Patches

Share
Updated on June 17, 2026

If all three critical FortiSandbox vulnerabilities now have fixes, how many vulnerable deployments were still exposed when exploitation began over the weekend?

XOOMAR Intelligence

Analyst Take

72/ 100
High
4 sources analyzedMedium confidenceTrend10Freshness99Source Trust85Factual Grounding94Signal Cluster20

Unknown attackers are actively targeting three Fortinet FortiSandbox flaws that can let remote attackers bypass authentication, escalate privileges, and run malicious code, according to The Register Security. Fortinet patched two of the bugs in April and the third last week, but threat intelligence firm Defused says exploitation is now underway.

Which FortiSandbox vulnerabilities are being exploited now?

The three bugs are CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. All carry 9.1 CVSS ratings. Fortinet said at patch time that it had no reports of active exploitation, according to the source material, but Defused now says attackers are hitting them.

“We are observing exploitation of multiple Fortinet FortiSandbox vulnerabilities during the past 24 hours,” Defused said in a LinkedIn post on Monday.

Defused said exploitation began over the weekend. SecurityWeek also reported that Defused honeypots saw attempts against all three CVEs, and that KEVIntel independently observed exploitation of CVE-2026-39808 on June 12 and attacks targeting CVE-2026-39813 on June 15.

Here is the patch map security teams need first:

CVE Flaw type Affected products and versions Fixed path
CVE-2026-39813 Path traversal in FortiSandbox JRPC API, enabling authentication bypass through specially crafted HTTP requests FortiSandbox 4.4.0 through 4.4.8 and 5.0.0 through 5.0.5 Upgrade to 4.4.9+ or 5.0.6+
CVE-2026-39808 OS command injection allowing unauthenticated code or command execution through HTTP requests FortiSandbox 4.4.0 through 4.4.8 Upgrade to FortiSandbox 4.4.9 or above
CVE-2026-25089 OS command vulnerability allowing unauthenticated command execution through specially crafted HTTP requests FortiSandbox 4.4.0 through 4.4.8, 5.0.0 through 5.0.5, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 Upgrade to a fixed version

Fortinet credited Loic Pantano, a Fortinet security analyst, with finding CVE-2026-39813. It credited KPMG Spain researcher Samuel de Lucas Maroto with finding and reporting CVE-2026-39808.

Why do these FortiSandbox bugs demand faster patching than routine CVEs?

The short answer: the flaws are critical, remote, and now observed in the wild.

A sandbox product is part of a security team’s defensive machinery. FortiSandbox is used for analyzing suspicious files and behavior, so a critical bug in that layer is not just another appliance maintenance item. XOOMAR analysis: when a flaw allows unauthenticated command execution or authentication bypass, the practical response window shrinks because attackers don’t need valid credentials to start probing vulnerable systems.

The hardest part for defenders is the attacker profile. The source material does not identify who is exploiting the bugs, how many targets have been hit, or whether successful compromise has been confirmed beyond exploit attempts. That matters because motive and target selection remain opaque.

Defused also flagged an unusual detail on CVE-2026-25089.

“Per our research a working exploit for CVE-2026-25089 has not yet been publicly disclosed,” Defused said.

The firm added that the exploit for that flaw appeared to be “vibe coded” and may be faulty. In this context, that means it appeared to be generated with AI-assisted coding from prompts rather than carefully built by hand. That does not make it harmless. Broken exploit code can still improve quickly once attackers test it against real targets.

For readers tracking the Fortinet patch cycle, XOOMAR’s related FortiSandbox coverage, Hackers Pounce on FortiSandbox Vulnerabilities After Fixes, is a useful companion to this update.


Which Fortinet versions should security teams check first?

Start with version inventory. The affected ranges are specific, and that makes the first decision simple: any FortiSandbox 4.4.0 through 4.4.8 should be treated as exposed until upgraded. The same applies to FortiSandbox 5.0.0 through 5.0.5 for the flaws that affect the 5.0 branch.

Security teams using FortiSandbox Cloud 5.0.4 through 5.0.5 or FortiSandbox PaaS 5.0.4 through 5.0.5 also need to confirm they are on fixed versions for CVE-2026-25089.

The immediate checklist is narrow:

  • Inventory: Identify every FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS deployment.
  • Compare: Match versions against the affected ranges above.
  • Upgrade: Move to 4.4.9+, 5.0.6+, or the relevant fixed version.
  • Verify: Confirm the appliance actually reports the patched version after maintenance.
  • Review: Check Fortinet advisories and threat intelligence updates for any new indicators or mitigation notes.

XOOMAR analysis: because Defused and KEVIntel observed exploitation after patches were available, patch status alone should not be the final step for systems that were vulnerable over the weekend. Teams should review relevant access logs, administrative events, network connections, and recent configuration changes for activity around the reported observation dates.

Fortinet did not respond to The Register’s inquiries about the three CVEs or whether the vendor had also observed attacks. That leaves defenders dependent on public advisories and outside threat intelligence for now.

How much will remain unknown after the patches are installed?

A lot. Patching closes the known holes, but it does not answer whether attackers landed on any exposed systems before upgrades were completed.

The Register also pointed to a separate warning earlier this month from Check Point VP of research Lotem Finkelstein, who said ransomware criminals had exploited a critical authentication bypass affecting Fortinet Remote Access VPN and Mobile Access deployments, and that the same crew was likely abusing other VPN-related Fortinet vulnerabilities. For broader VPN exposure context, see XOOMAR’s explainer on how VPN split tunneling can leak more than you expect online.

The next pressure point is CVE-2026-25089. Defused says a working public exploit was not yet disclosed, and the observed exploit may be faulty. If that changes, unpatched systems move from theoretical exposure to a much more crowded target list.

For Fortinet customers, the practical takeaway is blunt: upgrade first, verify second, investigate third. Then keep watching Fortinet notices, Defused updates, and other threat intelligence feeds for signs that today’s exploit attempts have turned into confirmed compromises.

Impact Analysis

  • All three flaws are critical and are now being targeted despite patches already being available.
  • The bugs can enable authentication bypass, privilege escalation, and malicious code execution against FortiSandbox deployments.
  • Security teams need to verify upgrades quickly because exploitation began shortly after the latest fix was released.

FortiSandbox vulnerabilities under active exploitation

CVECVSSKnown issueAffected versions / fixExploitation signal
CVE-2026-398139.1Path traversal in FortiSandbox JRPC API enabling authentication bypass via crafted HTTP requestsFortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5; upgrade to 4.4.9+ or 5.0.6+KEVIntel observed attacks on June 15; Defused saw exploitation over the weekend
CVE-2026-398089.1OS command injection allowing unauthenticated attack activityPatch available; exact affected versions not specified in excerptKEVIntel observed exploitation on June 12; Defused saw exploitation over the weekend
CVE-2026-250899.1Critical FortiSandbox flawPatch available; exact affected versions not specified in excerptDefused honeypots saw attempts against all three CVEs

CVSS severity of exploited FortiSandbox flaws

CVE-2026-39813
CVSS9.1
CVE-2026-39808
CVSS9.1
CVE-2026-25089
CVSS9.1
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Dark data center with breached digital shields and locks symbolizing exploited RCE in an AI platform.Cybersecurity

ServiceNow CVE-2026-6875 Hands Hackers an RCE Path

ServiceNow CVE-2026-6875 is being exploited, giving unauthenticated attackers an RCE path into unpatched AI Platform instances.

Jul 20, 20266 min
Threat hunter silhouette warning a shadowy hacker amid locks, shields, and dark cybersecurity visuals.Cybersecurity

Huntress Insider Threat Alarm Puts Client Trust on Trial

A Huntress staffer warned a ransomware actor about law enforcement interest. The CEO calls it poor judgment. Critics call it an insider threat.

Jul 4, 20268 min
Chain-locked book, phone, and laptop symbolizing digital and intellectual security.Cybersecurity

Feds Set Deadline as Hackers Hit AI Tool, Web Server Code

The US government has issued a mandatory remediation deadline after confirming attackers are actively exploiting critical bugs in Langflow, Apache Tomcat, and N

Aug 6, 20265 min
AI cyber defense shield protecting servers from opposing autonomous attack networksCybersecurity

AI Hackers Push Horizon3 to a $250M Cyber War Chest

Horizon3 raised $250M at a $2B valuation, turning autonomous pentesting into a high-stakes bet against AI-driven attacks.

Aug 3, 20266 min
Pop music studio under cyberattack with locks, shields, code matrix, and shadowy hackers.Cybersecurity

45 Songs Stolen as Ariana Grande Lawsuit Hunts Hackers

Grande says hackers stole 45 unreleased songs in 2023 alone. The lawsuit aims to name the people selling her private files.

Aug 2, 20265 min
Close-up image of ethernet cables plugged into a network switch, showcasing IT infrastructure.Technology

Chinese Routers Hide Secret Backdoor in 'Maintenance' Firmware

Security researchers found a hidden remote control trojan, dubbed ENDLESSDOORS, embedded in the firmware of over 20 Zbtlink router models, which the Chinese ven

Aug 6, 20266 min
Detailed close-up of a network Ethernet cable showing connectors on a black background.Technology

Average NBN Plan Cost Jumps, Pushing Speed Deserts

For just $7 more per month than a basic NBN 50 plan, Aussies can now get ten times the speed, making 500Mbps the new value leader for households.

Aug 7, 20267 min
Close-up of smartphone on wooden surface displaying a bank alert message.Fintech

Chime Crushes Banks with Fee-Free Profitability

Chime's profitable, fee-free model, powered by debit card spending, proves neobanks don't need to act like traditional banks to succeed.

Aug 7, 20269 min
Minimalistic display of OpenAI logo on a monitor with a gradient blue background, representing modern technology.Technology

OpenAI's Doughnut Speaker Builds Moving AI Personality

OpenAI's first hardware is a portable, $300 'doughnut' speaker with moving parts, engineered to be an 'AI-first computer' that learns your personality, not just

Aug 7, 20265 min
From above of sunlit aged paper world map with continents countries and oceansGlobal Trends

Trump Slaps 15% Tariff on China's Chip Silicon

A new US policy levies a 15% tariff and minimum price on imported polysilicon, directly targeting Chinese control over the foundational material for chips and s

Aug 7, 20268 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.