DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-39808PUBLISHED: 2026-04-14
CRITICALCVE-2026-39808★ CISA KEV LISTED

Fortinet FortiSandbox OS Command Injection Unauthenticated RCE

VENDOR: Fortinet//PRODUCT: FortiSandbox / FortiSandbox PaaS
9.8
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

An improper neutralization of special elements in OS commands (CWE-78) at the /fortisandbox/job-detail/tracer-behavior endpoint allows unauthenticated attackers to inject shell metacharacters via the jid parameter, executing commands with system-level privileges. CrowdSec detected 49 unique malicious IPs in the early exploitation phase, with first in-the-wild exploitation observed June 17, 2026. Public PoC exploit code and a Nuclei detection template are available on GitHub. CISA added to KEV July 16, 2026; security researchers demonstrated chaining with CVE-2026-39813 for unauthenticated root access.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSFortiSandbox 4.4.0 through 4.4.8; FortiSandbox PaaS (prior to 5.0.6); fixed in 4.4.9+ and 5.0.6+
  • https://arcticwolf.com/resources/blog/cve-2026-39808/
  • https://www.crowdsec.net/vulntracking-report/cve-2026-39808-fortinet-fortisandbox-command-injection
  • https://threatprotect.qualys.com/2026/06/17/fortinet-fortisandbox-vulnerability-exploited-by-attackers-cve-2026-39808-cve-2026-25089-cve-2026-39813/
  • https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog
SHARE BRIEF:✕ Post on Xin Share on LinkedIn