Skip to content
COOEY

EXPOSURES › CVE-2026-39808

CVE-2026-39808

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-07-16 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-39808 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 90/100 rceexploited-in-wildunpatched

Fortinet FortiSandbox OS Command Injection actively exploited without patch

Fortinet's FortiSandbox OS Command Injection vulnerability was exploited in the wild, allowing unauthenticated attackers to execute arbitrary code via crafted HTTP requests.

Shame score — Active exploitation without a patch, indicating negligence and a severe risk to DIB systems relying on FortiSandbox.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.