Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryembedded-device-vulnerabilityperimeter-device-exposureinternet-facing-service-vulnerability

Fortinet Patches Critical FortiSandbox and FortiManager Command-Execution Flaws

Updated 7d agoFirst seen Mar 10, 202622 sources

Fortinet issued multiple 2026 security advisories covering a broad set of vulnerabilities across FortiSandbox, FortiManager, FortiAnalyzer, FortiOS, FortiAP, FortiProxy, FortiPAM, FortiSwitchManager, FortiSwitchAXFixed, and related cloud offerings. The most severe flaws affect FortiSandbox, including CVE-2026-39808, an unauthenticated OS command injection bug that could allow arbitrary command execution and full device compromise, CVE-2026-39813, a path traversal issue in the JRPC API that may enable authentication bypass and privilege escalation, and CVE-2026-26083, a missing authorization flaw that can expose restricted functionality and sensitive sandbox analysis data through the GUI without authentication. National cyber authorities in Canada and Belgium separately warned organizations to apply Fortinet’s fixes immediately.

Fortinet also disclosed high-risk issues in management platforms, notably CVE-2025-54820, a stack-based buffer overflow in the FortiManager fgtupdates service that can let remote unauthenticated attackers execute unauthorized commands when the service is enabled, as well as a heap-based buffer overflow affecting FortiAnalyzer Cloud and FortiManager Cloud. Additional weaknesses across the product line include authentication and MFA bypasses, SQL injection, API denial of service, CLI command injection in FortiAP, CAPWAP daemon memory corruption in FortiOS, stored and reflected XSS, improper access control, and credential exposure. Fortinet advised customers to upgrade to fixed releases, disable exposed services such as fgtupdates where possible, restrict CLI, SSH, and API access, and monitor logs for anomalous authentication, privilege escalation, and endpoint activity.

Share:
Fortinet Patches Critical FortiSandbox and FortiManager Command-Execution Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jun 16, 20269d ago

Defused reports active exploitation of FortiSandbox flaws

On 2026-06-16, BleepingComputer reported Defused had observed active exploitation of multiple critical Fortinet FortiSandbox vulnerabilities, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The report said exploitation was seen within the previous 24 hours, marking a shift from disclosed vulnerabilities to confirmed in-the-wild attacks.

Critical Fortinet FortiSandbox flaws now exploited in attacks
Jun 11, 202614d ago

Belgium CCB warns to patch critical FortiSandbox command injection flaw

On 2026-06-11, Belgium's Centre for Cybersecurity published an advisory warning about Fortinet's critical FortiSandbox command injection vulnerability and urged organizations to patch immediately. The notice concerns the FortiSandbox flaw previously disclosed by Fortinet affecting FortiSandbox products.

Warning: Fortinet Addresses a Critical Command Injection Vulnerability in FortiSandbox, patch immediately! | CCB Belgium
Jun 9, 202616d ago

VulnCheck first observes exploitation of CVE-2026-39808

Researchers at VulnCheck first observed active exploitation of FortiSandbox vulnerability CVE-2026-39808 on 2026-06-09. The later CyberScoop report said this exploitation began after Fortinet had disclosed and patched the flaw in April.

Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April | CyberScoop

Fortinet discloses critical FortiSandbox OS command injection flaw

On 2026-06-09, Fortinet published advisory FG-IR-26-141 for CVE-2026-25089, a critical OS command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. The flaw allows unauthenticated remote attackers to execute arbitrary operating system commands via the web interface, and Fortinet issued fixed-version and mitigation guidance.

Fortinet FortiSandbox Vulnerability Allows Attackers to Execute Unauthorized Commands
May 14, 20261mo ago

Belgium CCB warns to patch Fortinet vulnerabilities immediately

On 2026-05-14, Belgium's Centre for Cybersecurity issued an advisory warning about multiple critical, high, and medium vulnerabilities in Fortinet FortiSandbox, FortiOS, FortiAP, FortiAnalyzer, and FortiManager. The notice urged immediate patching.

Warning: Multiple critical, high and medium vulnerabilities in Fortinet FortiSandbox, FortiOS, FortiAP, FortiAnalyzer, FortiManager, Patch Immediately! | CCB Belgium
May 12, 20261mo ago

Fortinet publishes May advisories for five vulnerabilities

On 2026-05-12, Fortinet published security advisories for five vulnerabilities affecting FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS, FortiAP, FortiAnalyzer, FortiManager, and FortiOS. The most severe was CVE-2026-26083, a critical missing authorization flaw in FortiSandbox products that could be exploited remotely without authentication through the GUI to access restricted functionality or sensitive analysis data.

Fortinet Patches Five Vulnerabilities Across FortiAP, FortiOS, and Enterprise Products
Apr 14, 20262mo ago

Fortinet publishes April advisories for 11 vulnerabilities

On 2026-04-14, Fortinet released security advisories addressing 11 vulnerabilities across FortiSandbox, FortiAnalyzer Cloud, FortiManager Cloud, FortiOS, FortiProxy, FortiPAM, FortiSwitchManager, and FortiDDoS-F. The most serious issues included critical unauthenticated FortiSandbox flaws enabling command execution, authentication bypass, and privilege escalation, plus a high-severity heap-based buffer overflow in cloud products.

Fortinet security advisory (AV26-351) - Canadian Centre for Cyber Security
Mar 10, 20264mo ago

Fortinet discloses FortiManager fgtupdates buffer overflow flaw

On 2026-03-10, Fortinet published advisory FG-IR-26-098 for CVE-2025-54820, a high-severity stack-based buffer overflow in the FortiManager fgtupdates service. The flaw could allow remote unauthenticated attackers to execute unauthorized commands under certain conditions, and Fortinet provided fixed-version guidance and a workaround to disable fgtupdates.

Fortinet FortiManager fgtupdates Vulnerability Allows Attackers to Execute Malicious Commands

Fortinet issues March advisories for 11 vulnerabilities across enterprise products

On 2026-03-10, Fortinet published security advisories covering eleven vulnerabilities affecting products including FortiManager, FortiAnalyzer, FortiSwitchAXFixed, and FortiSandbox/FortiSandbox Cloud. The issues included buffer overflows, authentication and MFA bypasses, TLS validation weaknesses, OS command injection, privilege escalation, SQL injection, format string exposure, and stored XSS.

Fortinet Security Update - Patch for Multiple Vulnerabilities That Enable Malicious Command Execution
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

48 LINKEDOpen in app
Affected products
16 linked
FortimanagerFortianalyzerFortisandboxFortisandbox Cloud Fortisandbox PaasFortiosFortiap-W2FortiapFortimanager CloudFortianalyzer CloudFortiproxyFortiswitchmanagerFortianalyzer-BigdataFortipamFortiap-UFortiswitchaxfixed
Organizations
5 linked
FortinetLinkedinXDBAppSecurityGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.