EXPOSURES › CVE-2026-39808
CVE-2026-39808
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 90/100
rceexploited-in-wildunpatched
Fortinet FortiSandbox OS Command Injection actively exploited without patch
Fortinet's FortiSandbox OS Command Injection vulnerability was exploited in the wild, allowing unauthenticated attackers to execute arbitrary code via crafted HTTP requests.
Shame score — Active exploitation without a patch, indicating negligence and a severe risk to DIB systems relying on FortiSandbox.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.