2026-06-12HIGHexploitedDefused reports exploitation of three pre-auth FortiSandbox flaws and CISA lists two in KEV; upgrading to 5.0.6 or 4.4.9 fixes all three
Fortinet FortiSandbox Cloud
product · product:fortinet-fortisandbox-cloud
Coverage
1
first 2026-06-12 → last 2026-09-30
Latest activity
2026-06-17
Defused reports exploitation of three pre-auth FortiSandbox flaws and CISA lists two in KEV; upgrading to…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology, defense · regions: europe
Sources cited
8
6 hosts
Action items (1)
Do-now tasks recorded on the entries about Fortinet FortiSandbox Cloud, newest first. Check the date before acting on an older one.
- Upgrade every FortiSandbox on the 5.0 or 4.4 branch to 5.0.6 or 4.4.9, which fixes all three flaws Defused reports exploited (CVE-2026-25089, CVE-2026-39808, CVE-2026-39813), and confirm the web UI and JRPC API answer only from the management network.2026-06-12CVE-2026-25089 +2
Defender insights
What each entry about Fortinet FortiSandbox Cloud tells a defender to do, newest first.
Exposure · detection
Story timeline
Hunting pivots
CVEs (exploited first)
Releases covered
Fortinet FortiSandbox Cloud
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-06-12/cve-2026-25089-fortinet-fortisandbox-unauthenticated-os-comm · ATT&CK page ↗
Entries about Fortinet FortiSandbox Cloud (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Fortinet FortiSandbox×1
- Fortinet FortiSandbox PaaS×1
- Fortinet FortiSandbox, JRPC API OS command injection (CVSS 9.8); actively exploited×1
- Fortinet FortiSandbox, JRPC API path traversal / auth bypass (CVSS 9.1); actively exploited×1
- FortiSandbox unauthenticated OS command injection in VNC handler (CVSS 9.8); dropped from brief - no inclusion gate cleared×1
Where this entity is cited
Source distribution
- fortiguard.fortinet.com3 (38%)
- advisories.ncsc.nl1 (12%)
- ccb.belgium.be1 (12%)
- cisa.gov1 (12%)
- helpnetsecurity.com1 (12%)
- securityaffairs.com1 (12%)
All cited sources (8)
- advisories.ncsc.nlNCSC-NL NCSC-2026-0189https://advisories.ncsc.nl/advisory?id=NCSC-2026-0189
- ccb.belgium.beCCB Belgiumhttps://ccb.belgium.be/advisories/warning-fortinet-addresses-critical-command-injection-vulnerability-fortisandbox-patch
- cisa.govCISA KEV cataloghttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- fortiguard.fortinet.comFortinet PSIRT FG-IR-26-100https://fortiguard.fortinet.com/psirt/FG-IR-26-100
- fortiguard.fortinet.comFortinet PSIRT FG-IR-26-112https://fortiguard.fortinet.com/psirt/FG-IR-26-112
- fortiguard.fortinet.comFortinet PSIRT FG-IR-26-141https://fortiguard.fortinet.com/psirt/FG-IR-26-141
- helpnetsecurity.comHelp Net Security, 2026-06-16https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/
- securityaffairs.comSecurity Affairs, 2026-06-16https://securityaffairs.com/193709/ai/fortinet-warned-as-three-critical-fortisandbox-bugs-come-under-attack.html