ctipilot.ch

Fortinet FortiSandbox — JRPC API path traversal / auth bypass (CVSS 9.1); actively exploited

cve · CVE-2026-39813

Coverage timeline
2
first 2026-06-17 → last 2026-06-22
Peak priority
high
1 high · 1 notable
Sources cited
2
2 hosts
Sections touched
2
updates, weekly-vuln-rollup
Co-occurring entities
2
see Related entities below
ATT&CK techniques
0
no mapped behavior yet

Story timeline

  1. 2026-06-22CVE-2026-25089 / CVE-2026-39808 / CVE-2026-39813 — FortiSandbox: three critical flaws exploited in one 24-hour window
    weekly-vuln-rollup
  2. 2026-06-17FortiSandbox — three critical flaws now exploited simultaneously, including the previously disclosure-only CVE-2026-25089
    updates

Where this entity is cited

  • updates1
  • weekly-vuln-rollup1

Source distribution

  • helpnetsecurity.com1 (50%)
  • securityaffairs.com1 (50%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Fortinet FortiSandbox — JRPC API path traversal / auth bypass (CVSS 9.1); actively exploited (2)

2026-06-22 · view entry permalink →

NOTABLECVE-2026-39808 +2exploited

CVE-2026-25089 / CVE-2026-39808 / CVE-2026-39813 — FortiSandbox: three critical flaws exploited in one 24-hour window

What was disclosure-only on 06-12 became active exploitation this week: Defused Cyber reported three FortiSandbox flaws exploited within a single 24-hour window — a JRPC OS command injection (CVE-2026-39808, 9.8), a JRPC path-traversal/auth-bypass (CVE-2026-39813, 9.1), and the web-UI command injection (CVE-2026-25089, 9.8) (Security Affairs; daily 06-17). FortiSandbox supplies the verdicts FortiGate, FortiMail, FortiProxy and FortiClient consume, so a compromised sandbox can suppress detection across the dependent Fortinet stack. The CVE-2026-25089 in-the-wild exploit appears AI-generated and faulty yet still finds traction against unpatched interfaces; Fortinet has not officially confirmed exploitation. Patch all three and restrict management-interface exposure.

What was disclosure-only on 06-12 became active exploitation this week: Defused Cyber reported three FortiSandbox flaws exploited within a single 24-hour window — a JRPC OS command injection (CVE-2026-39808, 9.8), a JRPC path-traversal/auth-bypass (CVE-2026-39813, 9.1), and the web-UI command …

ctipilot v2 brief (migrated)
vulnerability22 Jun 00:14Zmulti-sourceOpen finding ↗

2026-06-17 · view entry permalink →

HIGHCVE-2026-39808 +2exploitedupdate

FortiSandbox — three critical flaws now exploited simultaneously, including the previously disclosure-only CVE-2026-25089

UPDATE · originally covered CVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8) (2026-06-12)

When CVE-2026-25089 was covered on 06-12 it was disclosure-only. Threat-intel firm Defused Cyber has now reported active exploitation of three FortiSandbox flaws within a single 24-hour window — CVE-2026-39808 (CVSS 9.8, JRPC OS command injection), CVE-2026-39813 (CVSS 9.1, JRPC path traversal / auth bypass), both with patches available since April 2026, and CVE-2026-25089 (CVSS 9.8, web-UI command injection), patched 2026-06-09 (Security Affairs, 2026-06-16).

FortiSandbox supplies sandboxed file verdicts that FortiGate, FortiMail, FortiProxy and FortiClient consume to make blocking decisions, so a compromised sandbox can suppress detection across the dependent Fortinet stack (Help Net Security, 2026-06-16). The CVE-2026-25089 exploit seen in the wild appears AI-generated and is assessed as faulty, yet still finds traction against unpatched deployments — evidence that exposed, unpatched FortiSandbox interfaces remain. Fortinet has not yet officially confirmed exploitation. Patch all three; until then, restrict management-interface exposure and watch FortiSandbox web-UI/JRPC access logs for unauthenticated external POSTs.

UPDATE (originally covered 2026-06-12): When CVE-2026-25089 was covered on 06-12 it was disclosure-only.

ctipilot v2 brief (migrated)
vulnerability17 Jun 05:14Zmulti-sourceOpen finding ↗