Find notable cyber news and cases, enriched with sources, timelines, and signals.

Fortinet FortiSandbox multi-CVE exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 49
2 unique sources, 2 articles

Summary

Hide ▲

Fortinet FortiSandbox is facing an active exploitation wave that puts affected deployments at risk of unauthenticated remote code execution and privilege escalation. Defused said attackers are exploiting multiple critical vulnerabilities, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The activity was observed during the past 24 hours, and Fortinet had already released fixes on April 14. Administrators need to move to the latest released versions to block incoming attacks.

Related Happenings

FortiBleed multi-vendor brute-force wave

Exploitation Wave
H score75 First: 23.06.2026 21:20 Last: 23.06.2026 21:20 Sources 1

About this happening: A multi-vendor brute-force wave tied to FortiBleed is hitting Fortinet, Synology, Sophos, Citrix, RDWeb, and MS-SQL targets, expanding the risk from one firewall-focus...

CISA warning on FortiBleed for FortiGate customers

Public Sector Action
H score89 First: 19.06.2026 17:00 Last: 19.06.2026 17:00 Sources 1

About this happening: CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...

FortiSandbox unauthenticated command injection (CVE-2026-25089)

Vulnerability
H score47 First: 16.06.2026 13:30 Last: 16.06.2026 13:30 Sources 1

How related: CVE-2026-25089 (CVSS score: 9.1), on the other hand, was fixed last week, with Fortinet describing it as an operating system command injection impacting FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI that could allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

About this happening: CVE-2026-25089 is an unauthenticated operating system command injection in FortiSandbox-related products that was seen in active exploitation over the past 24 ho...

Fortinet security patch release for CVE-2026-39813

Security Patch Release
H score41 First: 16.06.2026 12:19 Last: 16.06.2026 12:19 Sources 1

How related: Fortinet released security updates for these three critical-severity security flaws (tracked as CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089) on April 14.

About this happening: Fortinet released April 14 security updates for FortiSandbox, covering CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The patch release fixes three...

FortiClient EMS CVE-2026-35616 exploitation wave

Exploitation Wave
H score56 First: 28.05.2026 18:26 Last: 28.05.2026 18:26 Sources 1

About this happening: CVE-2026-35616 exploitation in FortiClient Enterprise Management Server (EMS) is being used to deliver the undocumented credential stealer EKZ. Attackers are abusing u...

Timeline

  1. 16.06.2026 12:19 1 articles · 29d ago

    Fortinet releases April 14 fixes for critical FortiSandbox vulnerabilities

    Mitigation Patch Update

    Fortinet released security updates for CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 in FortiSandbox on April 14, addressing critical flaws that can let unauthenticated attackers escalate privileges and execute unauthorized code remotely through low-complexity command injection.

    Show sources
  2. 16.06.2026 12:19 3 articles · 29d ago

    Defused reports active exploitation of Fortinet FortiSandbox vulnerabilities

    Initial Disclosure

    Defused said attackers were actively exploiting multiple Fortinet FortiSandbox vulnerabilities during the past 24 hours, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The firm noted that CVE-2026-39813 had no previous recorded exploitation and that a working exploit for CVE-2026-25089 had not yet been publicly disclosed.

    Show sources