Particle.news
Download on the App Store

CISA Orders Federal Patch for Actively Exploited Fortinet FortiSandbox Flaws

CISA warned the unauthenticated command-injection bugs allow remote code execution with a risk of disrupting downstream Fortinet products.

Overview

  • CISA added the FortiSandbox flaws to its Known Exploited Vulnerabilities catalog on Thursday and required U.S. federal agencies to install Fortinet’s fixes by Sunday, July 19.
  • The bugs (notably CVE-2026-39808 and CVE-2026-25089) are unauthenticated OS command-injection flaws in the FortiSandbox web interface that let an attacker run system commands remotely with low complexity and no user interaction.
  • Fortinet has published patches for affected releases — FortiSandbox 4.4.9+ and 5.0.6+ (Cloud/PaaS 5.0.6+) — and urges immediate upgrades or isolation of the management web interface when patching is not possible.
  • A compromised FortiSandbox can have outsized impact because its malware verdicts are consumed by FortiGate, FortiMail, FortiWeb, and FortiProxy, which could cause incorrect blocking, policy changes, or automated enforcement across networks.
  • Threat intelligence firms reported exploitation attempts starting in mid-June and responders are advised to audit Fortinet integrations, hunt for signs of compromise, and verify firmware versions for all three actively exploited FortiSandbox CVEs.