<- ALL CYBER NEWS
Critical
Fortinet, FortiSandbox, CVE-2026-39808, CVE-2026-25089, CISA KEV, EPSS, command injection

Fortinet FortiSandbox CVE-2026-39808 Exploited in the Wild
Fortinet FortiSandbox CVE-2026-39808 and CVE-2026-25089 (both CVSS 9.8) are in CISA KEV and actively exploited. EPSS puts one at the 98.7th percentile.
CISA added two Fortinet FortiSandbox OS command injection flaws - CVE-2026-39808 and CVE-2026-25089, both CVSS 9.8 - to its Known Exploited Vulnerabilities catalog on 16 July, with a 19 July federal deadline. One carries an EPSS score in the 98.7th percentile. The security appliance is the attack surface.
What happened. CISA added CVE-2026-39808 and CVE-2026-25089 to the KEV catalog on 16 July 2026, deadline 19 July. Both are improper neutralisation of special elements in an OS command (CWE-78, OS command injection) in Fortinet FortiSandbox, and both score CVSS 9.8 critical.
How bad are the FortiSandbox flaws?
Metric | CVE-2026-39808 | CVE-2026-25089 |
|---|---|---|
CVSS | 9.8 Critical (CWE-78) | 9.8 Critical (CWE-78) |
Affected | FortiSandbox 4.4.0 - 4.4.8 | FortiSandbox 5.0.0 - 5.0.5, 4.4.x |
EPSS probability | 48.7% (98.7th percentile) | 23.4% (97.5th percentile) |
CISA KEV added | 2026-07-16 | 2026-07-16 |
Federal deadline | 2026-07-19 | 2026-07-19 |
Those EPSS numbers are the story. An EPSS of 48.7% puts CVE-2026-39808 in the 98.7th percentile of all scored vulnerabilities - roughly a coin flip that it is exploited within 30 days, and it is already confirmed in KEV.
Who is affected. Anyone running FortiSandbox 4.4.0-4.4.8 or 5.0.0-5.0.5. FortiSandbox is the appliance that detonates suspicious files for you - it sits deep in the trust chain, holds malware samples, and typically talks to the rest of your security stack.
What should you do now?
Patch to a fixed FortiSandbox build immediately - this is a three-day clock for federal agencies and should be the same for everyone else. Until then, restrict management access to trusted networks and review the appliance for unexpected OS command execution. Because both are KEV-listed, assume exploitation attempts predate your patch and hunt backward.
Our read. The uncomfortable part is not that a Fortinet product has a bug; it is that the thing being exploited is a security appliance. Defensive tooling gets deployed once, trusted permanently, and rarely tested like the internet-facing asset it actually is. In our 2025 KEV analysis, 67% of genuinely exploited vulnerabilities would have been missed by an annual pentest cadence - and appliances are exactly the assets that cadence skips. Your security stack is attack surface, and it needs the same continuous verification as everything else.
Vulnerability status per the CISA KEV catalog; severity, affected versions and CWE per NVD; exploit probability per FIRST.org EPSS. Sources linked above.
Related: SonicWall SMA 1000 zero-days and our KEV pentest analysis.
Frequently asked questions
Are the FortiSandbox flaws being exploited?
Yes. Both CVE-2026-39808 and CVE-2026-25089 are in CISA’s KEV catalog (added July 16, 2026). CVE-2026-39808’s EPSS score sits in the 99.7th percentile, among the most likely flaws on the internet to be exploited.
Which FortiSandbox versions are affected?
CVE-2026-39808 affects FortiSandbox 4.4.0 through 4.4.8. CVE-2026-25089 has a wider range: FortiSandbox 5.0.0–5.0.5, 4.4.0–4.4.8, 4.2 (all versions), and FortiSandbox Cloud 5.0.4–5.0.5.
What is the difference between CVE-2026-39808 and CVE-2026-25089?
Both are OS command-injection flaws (CWE-78, CVSS 9.8) that let an attacker execute unauthorized commands. CVE-2026-25089 covers a broader set of versions, including the 5.0.x branch and FortiSandbox Cloud.
How do I fix the FortiSandbox CVEs?
Upgrade to Fortinet’s fixed FortiSandbox release per the FortiGuard advisory, and keep the management interface off the public internet.
Affected versions and references
CVE-2026-39808: FortiSandbox 4.4.0 through 4.4.8.
CVE-2026-25089: FortiSandbox 5.0.0-5.0.5, 4.4.0-4.4.8, 4.2 (all versions), FortiSandbox Cloud 5.0.4-5.0.5.
Fix: upgrade to Fortinet's fixed release per the FortiGuard advisory.
References: NVD CVE-2026-39808 and the CISA KEV catalog.