Skip to content
COOEY

FAIL › dossier

FortiSandbox

PRODUCT

· dossier confidence 40%

Fortinet is a public cybersecurity leader with a critical flaw in its own FortiSandbox product that allows unauthenticated remote command execution. The company has a history of high-severity vulnerabilities in its security appliances that were actively exploited before patching.

PROFILE
CategoryvendorWhat they doFortinet, Inc. provides cybersecurity and convergence of networking and security solutions worldwide, including the FortiSandbox threat-analysis platform.Founded2000 Websitehttps://www.fortinet.com ↗
SECURITY POSTURE

Despite a strong market position, Fortinet has demonstrated critical vulnerabilities in its own security products, specifically in the FortiSandbox OS, with multiple high-severity command-injection flaws actively exploited before patching.

Notable failures
  • CVE-2026-39808: FortiSandbox OS Command Injection actively exploited
  • CVE-2026-25089: FortiSandbox OS Command Injection exploited before July 19, 2026
  • CVE-2026-39813: Part of chained exploit for unauthenticated root access
Patterns: Repeated unpatched edge-device RCEs; Chained vulnerabilities enabling unauthenticated root access
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2026-07-16 CVE-2026-39808 high Fortinet FortiSandbox OS Command Injection actively exploited without patch
2026-07-16 CVE-2026-25089 high Fortinet FortiSandbox OS Command Injection Vulnerability actively exploited before July 19, 2026
Open questions: What is the current status of CVE-2026-39813 remediation? · Are there additional unpatched vulnerabilities in FortiSandbox beyond the three identified?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-01 03:46:38.029680+00:00