# Active Exploitation of Critical Fortinet FortiSandbox Vulnerabilities Reported Hours After Latest Patch
Threat intelligence firm Defused Cyber is reporting real-world exploitation of three critical vulnerabilities affecting Fortinet FortiSandbox—including a flaw patched just one week ago. The vulnerabilities, all carrying a CVSS severity score of 9.1, allow unauthenticated attackers to execute arbitrary code or bypass authentication controls through specially crafted HTTP requests. Security teams relying on FortiSandbox for malware analysis and threat detection should treat this as an immediate priority.
## The Threat
Fortinet's FortiSandbox product family is a critical component in many enterprise security architectures, providing isolated execution environments to detonate and analyze malicious files before they reach end users. When the sandbox itself becomes an attack surface, it transforms from a defensive asset into a direct gateway to internal networks—particularly dangerous because sandboxes typically sit at network chokepoints and maintain access to threat intelligence systems and incident response infrastructure.
The three CVEs under active exploitation represent a combination of authentication bypass and command injection flaws that eliminate the need for valid credentials or multi-stage attacks. CVE-2026-39813, a path traversal vulnerability in FortiSandbox's JRPC API, permits attackers to bypass authentication entirely using specially crafted HTTP requests. CVE-2026-39808, an OS command injection flaw in the same API, allows unauthenticated execution of arbitrary commands. Both flaws were patched by Fortinet in April 2026—nearly two months before this exploitation wave. The third vulnerability, CVE-2026-25089, another OS command injection affecting the FortiSandbox web interface (including cloud and PaaS variants), was patched only six days ago on June 9, 2026.
The fact that attackers have already moved to exploit CVE-2026-25089 despite its recent patch window is particularly concerning and suggests either rapid reconnaissance of customer environments or prior knowledge of the vulnerability before public disclosure. Defused Cyber noted that the exploit code for this vulnerability bears signs of being generated by an artificial intelligence model and contains functional flaws—yet attackers are still deploying it, indicating either tooling maturity or trial-and-error exploitation campaigns.
## Severity and Impact
| CVE | CVSS Score | Vulnerability Type | Attack Vector | Authentication | Affected Component |
|---------|---|---|---|---|---|
| CVE-2026-39813 | 9.1 | Path Traversal / Authentication Bypass | Network (HTTP) | None Required | JRPC API |
| CVE-2026-39808 | 9.1 | OS Command Injection | Network (HTTP) | None Required | JRPC API |
| CVE-2026-25089 | 9.1 | OS Command Injection | Network (HTTP) | None Required | Web UI |
All three vulnerabilities are remotely exploitable without authentication, have a network attack vector, and allow arbitrary code execution or authentication bypass. Attack complexity is rated as low, meaning no special conditions or privileges are required to trigger the flaws.
## Affected Products
Fortinet has not published a detailed version matrix, but organizations should assume all installations deployed before the April 2026 patches (CVE-2026-39813 and CVE-2026-39808) and the June 9, 2026 patch (CVE-2026-25089) are at risk. Cloud and PaaS customers should verify with Fortinet that their instances have received the June patch.
## Mitigations
Immediate Actions (Next 24 Hours):
1. Apply Fortinet's security patches immediately for all three CVEs
2. If patching cannot be completed immediately, temporarily restrict network access to FortiSandbox management interfaces and APIs to trusted internal IP ranges
3. Enable detailed HTTP request logging on all FortiSandbox instances and begin searching logs for exploitation attempts targeting the JRPC and web UI endpoints
4. For cloud and PaaS customers, contact Fortinet support to confirm patch status and request expedited deployment if available
Short-Term Mitigations (1-7 Days):
1. Implement web application firewall rules to block requests containing path traversal sequences (../) and shell metacharacters targeting FortiSandbox endpoints
2. Segment FortiSandbox from direct internet exposure; place it behind a reverse proxy with strict request validation
3. Disable the JRPC API if it is not in active use at your organization
4. Rotate API tokens and administrative credentials for all FortiSandbox instances
5. Monitor FortiSandbox logs for signs of reconnaissance (failed authentication attempts, unusual API queries)
Detection and Monitoring:
/api/jrpc/ endpoints with unusual payloads or path traversal sequences## References
---
## HackWire Analysis
This exploitation wave highlights a troubling pattern: Fortinet's security posture is under sustained pressure from threat actors, and patches alone are insufficient if deployment pipelines cannot keep pace. The April 2026 patches for CVE-2026-39813 and CVE-2026-39808 represent a two-month patch window—yet attackers were still leveraging these flaws as of June 16, suggesting significant swaths of the installed base remain unpatched.
More concerning is the timing of CVE-2026-25089 exploitation. A vulnerability patched on June 9 being actively exploited by June 16 indicates either a pre-patch window where threat actors possessed knowledge of the flaw or an exceptionally rapid exploitation cycle after public disclosure. Defused Cyber's observation that the exploit code appears AI-generated is also noteworthy: it suggests threat actors are adopting large language models to accelerate exploit development, even when the resulting code is functionally flawed. The fact that faulty AI-generated code is still being deployed in attacks tells us that attackers are comfortable with low-accuracy exploitation attempts—they may be running broad campaigns knowing that a small percentage will succeed.
For defenders, the key takeaway is that FortiSandbox should no longer be treated as a low-security-risk component. It sits at a critical inflection point: it receives files from untrusted sources (external emails, downloads) and has direct access to threat intelligence feeds, SOAR playbooks, and often lateral network access. A compromise here is a beachhead into incident response and threat detection infrastructure.
Organizations should also consider whether their patch management processes are designed to handle zero-day-adjacent scenarios. The April patches were not marked as zero-day exploits, yet two months elapsed before widespread patching. If your change control process requires multiple approval gates and scheduled maintenance windows, FortiSandbox patches should receive expedited treatment—treat them as if they were emergency out-of-band releases.
Finally, this incident reinforces why network segmentation and least-privilege access are non-negotiable. FortiSandbox does not need unrestricted internet access or the ability to reach internal systems other than its designated feed sources. Every organization running FortiSandbox should assume it *will* be compromised at some point and architect accordingly.
— HackWire Editorial
---
## Related Coverage