The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for government agencies to prioritize patching two critical vulnerabilities currently being exploited in the Fortinet FortiSandbox threat detection platform.
These significant security flaws, identified as CVE-2026-39808 and CVE-2026-25089, were patched by Fortinet on April 14 and June 9, respectively.
According to a security advisory by Fortinet, these vulnerabilities allow unauthenticated attackers to remotely execute malicious code through low-complexity command injection attacks, which do not necessitate user interaction.
To mitigate these risks and safeguard against incoming attacks, administrators are advised to upgrade all affected FortiSandbox systems to the latest version.
While Fortinet has not officially classified these vulnerabilities as currently being exploited, threat intelligence firm Defused reported on June 16 that attackers have begun to leverage them in real-world scenarios.
Defused stated, “In the past 24 hours, we have observed the exploitation of multiple Fortinet FortiSandbox vulnerabilities, including CVE-2026-39813 (no known exploits to date), CVE-2026-39808, and CVE-2026-25089 (vibe-coded and potentially flawed exploit).” They cautioned.
CISA has also recognized these vulnerabilities, adding them to their Catalog of Known Exploited Vulnerabilities. Following Binding Operating Directive (BOD) 26-04, U.S. federal agencies are required to patch vulnerable FortiSandbox instances by Sunday, July 19.
Earlier this year, in February, Fortinet addressed a critical SQL injection vulnerability (CVE-2026-21643) in its FortiClient Enterprise Management Server (EMS) platform, which was flagged as actively exploited after one month.
Two months later, the company reported another security issue: a path traversal vulnerability (CVE-2025-61624) that allows authenticated attackers to escalate privileges.
Fortinet vulnerabilities are frequently exploited in cyber espionage and ransomware attacks, often as zero-day threats. In total, CISA tracks 28 Fortinet vulnerabilities that have been exploited in recent attacks, including 13 specifically in ransomware incidents.
Security teams document 54% of successful attacks but only issue warnings for 14%. The remaining attacks move silently through the environment.
Picus’ whitepaper outlines how to test your SIEM and EDR rules in breach and attack simulations to ensure threats are adequately detected.
Source: www.bleepingcomputer.com




