UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

FortiSandbox CVE Exploits: CISA's 2026 Patch Order Explained

London · Servnet News Desk · IT infrastructure analysis3 min read
Share

CISA has confirmed active exploitation of two critical FortiSandbox flaws, CVE-2026-39808 and CVE-2026-25089, both scoring 9.1 on CVSS. For UK organisations running Fortinet products, the emergency patch order is a signal to move now, not next quarter.

CVSS severity across the flaws in this week's CISA update
10 CVSS8 CVSS5 CVSS3 CVSS0 CVSS9.1 CVSSCVE-2026-398089.1 CVSSCVE-2026-250899.1 CVSSCVE-2026-398139.8 CVSSCVE-2026-58644CVSS score
View the data behind this chart
CVSS severity across the flaws in this week's CISA update
CVE-2026-39808CVE-2026-25089CVE-2026-39813CVE-2026-58644
CVSS scoreCVSS9.1CVSS9.1CVSS9.1CVSS9.8

What CISA actually confirmed

CISA has added CVE-2026-39808 and CVE-2026-25089 to its Known Exploited Vulnerabilities catalog, meaning the agency holds evidence of real-world exploitation even though it hasn't detailed scale or attribution. Both are OS command injection flaws affecting FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS, letting unauthenticated attackers run arbitrary commands via crafted HTTP requests, no credentials or user clicks required.

Fortinet itself has not updated its advisories to mark either bug as exploited and declined to answer questions, which leaves customers relying on CISA and independent researchers for ground truth rather than the vendor.

Why the patch history matters

Fortinet shipped a fix for CVE-2026-39808 back in April and closed CVE-2026-25089 in June, in both cases warning that low-complexity attacks could lead to remote code execution. That gap between patch availability and confirmed in-the-wild exploitation is the uncomfortable part: these are not zero-days caught before a fix existed, they're bugs attackers are still finding value in weeks or months after remediation shipped.

Security firm Defused reported exploitation attempts against both flaws this week, plus a third FortiSandbox bug, CVE-2026-39813, in the same window. Notably, Defused described the exploit aimed at CVE-2026-25089 as 'vibecoded' and likely broken, with no working public exploit yet observed, a reminder that KEV listing doesn't always mean a polished attack chain is circulating.

What this means for UK buyers specifically

Binding Operational Directive 26-04 forces US federal civilian agencies to patch by CISA deadlines or disconnect vulnerable products. That directive has no legal force in the UK, but it's a useful proxy for how seriously to treat the exposure. Any organisation running FortiSandbox on-premises, or consuming the Cloud or PaaS variants, should treat this as an immediate patching action rather than something to schedule around change windows.

This isn't Fortinet's first appliance-class scare, and it follows a pattern seen across the whole SMA and sandbox appliance category. UK teams that dealt with similar zero-day exploits on SonicWall SMA gear will recognise the shape of this incident: internet-facing security appliances, unauthenticated command execution, and a lag between patch release and confirmed exploitation.

Illustration: FortiSandbox CVE Exploits: CISA's 2026 Patch Order Explained

The bigger appliance-security pattern

FortiSandbox joins a growing list of Fortinet products hit by serious, actively exploited bugs, including the FortiCloud SSO flaw Fortinet had to block at the network level while a patch was prepared, and last year's mass exploitation of FortiGate firewalls tied to an authentication bypass. For buyers, the lesson isn't that Fortinet is uniquely troubled, it's that any internet-facing security appliance, from any vendor, is now a preferred target precisely because it sits with elevated trust inside the network perimeter.

That reality strengthens the case for treating vulnerability management strategies as a continuous discipline rather than a quarterly patch cycle, with asset inventories that specifically flag internet-exposed sandbox, VPN and SSO appliances for accelerated review.

Don't forget the SharePoint bug riding along

CISA used the same KEV update to flag a separate, unrelated critical flaw: Microsoft's SharePoint Server bug CVE-2026-58644, rated 9.8, which lets an attacker with Site Owner privileges execute arbitrary code via deserialisation. Microsoft has warned it can be exploited remotely over the internet with relatively little effort. It's a useful reminder that patch cycles this month are stacking up across multiple vendors, not just Fortinet, and prioritisation matters as much as speed.

What UK teams should do this week

Confirm every FortiSandbox instance, on-prem, Cloud, or PaaS, is running a version that includes fixes for both CVE-2026-39808 and CVE-2026-25089, and check for CVE-2026-39813 exposure too given the parallel exploitation attempts. Where patching can't happen immediately, restrict management interface access and monitor for anomalous HTTP requests hitting sandbox web UIs.

Longer term, this incident is another argument for layering managed detection & response around appliance-heavy estates and evaluating zero trust segmentation so a compromised sandbox or SSO appliance can't pivot freely. Teams reassessing their edge security stack more broadly may also want to compare options via our best firewall solutions guide and review network security solutions that reduce reliance on any single exposed appliance.

Share
Key takeaways
  • Two critical FortiSandbox flaws (CVE-2026-39808, CVE-2026-25089), both CVSS 9.1, are confirmed under active exploitation by CISA via KEV listing.
  • Fortinet patched both bugs months ago (April and June) but has not confirmed exploitation itself, leaving CISA and researchers as the primary signal.
  • A third FortiSandbox bug, CVE-2026-39813, is also seeing exploitation attempts, though one exploit chain was assessed as broken.
  • Microsoft's SharePoint bug CVE-2026-58644 (CVSS 9.8) landed in the same KEV update, adding to this month's patch backlog for UK IT teams.
Frequently asked

FAQs — FortiSandbox CVE Exploits

Has Fortinet confirmed FortiSandbox is being exploited?

No. Fortinet has not updated its advisories to mark either CVE-2026-39808 or CVE-2026-25089 as exploited and did not respond to questions, though CISA's KEV listing confirms it has evidence of active exploitation.

Which FortiSandbox products are affected?

FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS are all listed as affected by the OS command injection flaws, exploitable via crafted HTTP requests without authentication.

Are UK organisations bound by CISA's patch directive?

No, Binding Operational Directive 26-04 applies to US federal civilian agencies. UK organisations aren't legally bound but should treat the KEV listing as a strong signal to prioritise patching, much as they would for Fortinet cybersecurity solutions generally.

Is there a working public exploit for these bugs?

Security firm Defused says it has not seen a working public exploit for CVE-2026-25089, describing the observed attempt as likely broken, though exploitation attempts against all three FortiSandbox CVEs have been observed.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111