Hackers actively exploit critical Fortinet FortiSandbox flaws
Researchers say attackers are actively exploiting three critical vulnerabilities in Fortinet's FortiSandbox, the appliance many companies trust to catch threats. The bugs need no login or user action to run commands and seize control. Defused logged forty-nine exploit events from eleven addresses across nine countries in six days. Admins should patch to the latest version.
Security researchers warn that hackers are actively exploiting three critical vulnerabilities in Fortinet's FortiSandbox ($FTNT), the very appliance organizations rely on to inspect suspicious files and detect emerging threats. The flaws, tracked as CVE-2026-39808, CVE-2026-39813 and CVE-2026-25089, were patched by Fortinet in April and June 2026, but exploitation began almost immediately. They let an unauthenticated attacker bypass login, escalate privileges and run commands with no user interaction. The threat intelligence firm Defused logged forty-nine exploitation attempts from eleven separate addresses over just six days, traced to thirteen sources across nine countries including China, South Korea, Taiwan, India, Singapore, Germany, the Netherlands, Canada and Bulgaria. The spread points to several independent operators rather than a single coordinated campaign. Because a sandbox ingests data from and connects to other Fortinet devices, compromising it hands attackers a trusted foothold deep inside the network, and these appliances often lack the detailed logging needed to spot an intrusion. Sources: CyberScoop, BleepingComputer, Cybersecurity Dive.