The images in this article were generated with artificial intelligence. How we publish
Fortinet was back in the spotlight after researchers from the Defused firm reported active exploitation of several critical vulnerabilities on his FortiSandbox threat analysis platform. The failures identified as CVE-2026-39813, CVE-2026-39808 and CVE-2026-25089 allow non-authenticated attackers to run command injection and scale privileges remotely without user interaction, a scenario that facilitates rapid intrusion and the deployment of malicious code in corporate environments.
Fortinet published patches for these vulnerabilities on April 14; however, the fact that exploits are being observed in nature indicates that adversaries take advantage of exposure windows in unpatched or poorly configured facilities. Defuse further warned that, although some available exploits seem defective, others show recent activity, and that at least one of the failures still did not have a known public exploitation test before it was detected for use in real attacks. You can review Fortinet's official notices about these incidents on the PSIRT page: CVE-2026-39813 and CVE-2026-39808.

This incident fits into a repeated pattern: Fortinet's perimetral security and endpoint management solutions have been frequently exploited by Ransomware groups and espionage actors, sometimes as zero-day vulnerabilities. The US Cybersecurity and Infrastructure Agency. US (CISA) maintains a catalogue of vulnerabilities exploited in nature and has sometimes required accelerated responses by agencies to critical failures in Fortinet technologies; consult the public register at CISA Known Exploited Vulnerabilities to see the historical scope.
For security teams and administrators this involves three urgent realities: first, the risk window exists as long as unpatched systems remain; second, many of these vulnerabilities allow remote execution without human interaction, which reduces detection time; and third, attackers often chain up several weaknesses (e.g., combination with privilege or traversal failures) to achieve persistence and lateral movement.
The practical and immediate actions I recommend are clear: apply the patches provided by Fortinet as soon as possible to all FortiSandbox applications and related management elements; if the patch cannot be deployed immediately, isolate the authorities concerned from the production network and restrict access to administration by access control lists, jump VPNs and network segmentation. In addition, enable and review connection logs, DDR / SIEM anomaly searches and detection rules focused on remote execution and command injection behaviors.
It is not enough to apply patches: recommend to your organization a retrospective search (hunt) in historical records to identify suspicious pre-patch activity, and validate the integrity of critical systems. If you detect compromise signals, proceed to disconnect the affected machine, preserve evidence and activate incident response to contain and eradicate intrusion; in many cases, the attackers who exploit these failures seek to install ansomware or to pivote to servers with sensitive information.

It is also important to review preventive settings and practices: limit which systems have administrative access to solutions such as FortiSandbox, apply multifactor authentication in management consoles, disable unnecessary services and reduce public exposure surface. Plot testing in staging environments and patch deployment automation help to avoid critical delays.
For teams interested in additional technical context, Fortinet and public vulnerability databases provide details that help prioritize response and mitigation; for example, Fortinet published specific notices and the NVD maintains technical chips for previous errors in its products, such as the correction of a SQLi in FortiClient EMS: CVE-2026-21643 (NVD). To remain subscribed to these sources and third party notifications allows to reduce the exposure window.
In short, the active exploitation of Fails in FortiSandbox is a reminder that no defense is infallible and that the combination of fast patches, segmentation, hard access controls and continuous monitoring is the best strategy to prevent critical vulnerability from becoming a major gap. If you give FortiSandbox, prioritize the update and check the integrity of your environments before declaring the incidence closed.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...