CISA has confirmed active exploitation of two critical FortiSandbox flaws, CVE-2026-39808 and CVE-2026-25089, both scoring 9.1 on CVSS. For UK organisations running Fortinet products, the emergency patch order is a signal to move now, not next quarter.
View the data behind this chart
| CVE-2026-39808 | CVE-2026-25089 | CVE-2026-39813 | CVE-2026-58644 | |
|---|---|---|---|---|
| CVSS score | CVSS9.1 | CVSS9.1 | CVSS9.1 | CVSS9.8 |
What CISA actually confirmed
CISA has added CVE-2026-39808 and CVE-2026-25089 to its Known Exploited Vulnerabilities catalog, meaning the agency holds evidence of real-world exploitation even though it hasn't detailed scale or attribution. Both are OS command injection flaws affecting FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS, letting unauthenticated attackers run arbitrary commands via crafted HTTP requests, no credentials or user clicks required.
Fortinet itself has not updated its advisories to mark either bug as exploited and declined to answer questions, which leaves customers relying on CISA and independent researchers for ground truth rather than the vendor.
Why the patch history matters
Fortinet shipped a fix for CVE-2026-39808 back in April and closed CVE-2026-25089 in June, in both cases warning that low-complexity attacks could lead to remote code execution. That gap between patch availability and confirmed in-the-wild exploitation is the uncomfortable part: these are not zero-days caught before a fix existed, they're bugs attackers are still finding value in weeks or months after remediation shipped.
Security firm Defused reported exploitation attempts against both flaws this week, plus a third FortiSandbox bug, CVE-2026-39813, in the same window. Notably, Defused described the exploit aimed at CVE-2026-25089 as 'vibecoded' and likely broken, with no working public exploit yet observed, a reminder that KEV listing doesn't always mean a polished attack chain is circulating.
What this means for UK buyers specifically
Binding Operational Directive 26-04 forces US federal civilian agencies to patch by CISA deadlines or disconnect vulnerable products. That directive has no legal force in the UK, but it's a useful proxy for how seriously to treat the exposure. Any organisation running FortiSandbox on-premises, or consuming the Cloud or PaaS variants, should treat this as an immediate patching action rather than something to schedule around change windows.
This isn't Fortinet's first appliance-class scare, and it follows a pattern seen across the whole SMA and sandbox appliance category. UK teams that dealt with similar zero-day exploits on SonicWall SMA gear will recognise the shape of this incident: internet-facing security appliances, unauthenticated command execution, and a lag between patch release and confirmed exploitation.

The bigger appliance-security pattern
FortiSandbox joins a growing list of Fortinet products hit by serious, actively exploited bugs, including the FortiCloud SSO flaw Fortinet had to block at the network level while a patch was prepared, and last year's mass exploitation of FortiGate firewalls tied to an authentication bypass. For buyers, the lesson isn't that Fortinet is uniquely troubled, it's that any internet-facing security appliance, from any vendor, is now a preferred target precisely because it sits with elevated trust inside the network perimeter.
That reality strengthens the case for treating vulnerability management strategies as a continuous discipline rather than a quarterly patch cycle, with asset inventories that specifically flag internet-exposed sandbox, VPN and SSO appliances for accelerated review.
Don't forget the SharePoint bug riding along
CISA used the same KEV update to flag a separate, unrelated critical flaw: Microsoft's SharePoint Server bug CVE-2026-58644, rated 9.8, which lets an attacker with Site Owner privileges execute arbitrary code via deserialisation. Microsoft has warned it can be exploited remotely over the internet with relatively little effort. It's a useful reminder that patch cycles this month are stacking up across multiple vendors, not just Fortinet, and prioritisation matters as much as speed.
What UK teams should do this week
Confirm every FortiSandbox instance, on-prem, Cloud, or PaaS, is running a version that includes fixes for both CVE-2026-39808 and CVE-2026-25089, and check for CVE-2026-39813 exposure too given the parallel exploitation attempts. Where patching can't happen immediately, restrict management interface access and monitor for anomalous HTTP requests hitting sandbox web UIs.
Longer term, this incident is another argument for layering managed detection & response around appliance-heavy estates and evaluating zero trust segmentation so a compromised sandbox or SSO appliance can't pivot freely. Teams reassessing their edge security stack more broadly may also want to compare options via our best firewall solutions guide and review network security solutions that reduce reliance on any single exposed appliance.
- 01The Register — Attackers target critical FortiSandbox flaws as CISA issues patch order · 17 July 2026
- 02The Register — Three critical Fortinet sandbox bugs splattered by unknown attackers · 16 June 2026
- 03BleepingComputer — Critical Fortinet FortiSandbox flaws now exploited in attacks · 16 June 2026
- 04The Hacker News — Attackers exploit three Fortinet FortiSandbox flaws · 16 June 2026
- 05BleepingComputer — Fortinet blocks exploited FortiCloud SSO zero-day until patch is ready · 1 January 2026
- 06The Register — Another bad week for SonicWall as SMA 1000 0-day exploited · 18 December 2025
