Skip to main content

CVE detail

CVE-2026-39808

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

CVSS 9.8 · CriticalBuzz score 81.8KEV listed2 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 81.8

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 28.3 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 8.5
Mention score
28.3
16 evidence mentions in the snapshot
Diversity score
20.0
10 sources across 5 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
8.5
2 repos · best confidence 0.90
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
6
within the 30d window
Peak daily
4
highest bucket

Evidence

Source links by recency

Newest mentions first
16 source links · newest first
  • CISA) added Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities (KEV) catalog . CVE-2026-25089 (CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-39808 (CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-58644 (CVSS score of 9.8) Microsoft Share

    newssecurityaffairs.comJul 18, 2026, 11:49 AM
  • endars after CISA confirmed a pair of critical FortiSandbox bugs are being actively exploited. The two bugs, tracked as CVE-2026-39808 and CVE-2026-25089, both carry CVSS scores of 9.1 and affect FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. According to Fortinet, they are OS command injection flaws that allow unauthenticated attackers to ex

    newswww.theregister.comJul 17, 2026, 11:58 AM
  • in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) has warned. The vulnerabilities, tracked as CVE-2026-39808 and CVE-2026-25089 are both critical, with a severity rating (CVSS) of 9.1 each. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog on July 16, suggesting evidence of observed exploitation in the wild.

    newswww.infosecurity-magazine.comJul 17, 2026, 9:45 AM
  • y remote code execution (RCE) vulnerability in Microsoft SharePoint, the US cybersecurity agency CISA warns. Tracked as CVE-2026-58644 (CVSS score of 9.8) and fixed as part of Microsoft’s July 2026 Patch Tuesday updates, the flaw is described as a deserialization of untrusted data issue. “In a network-based attack, an attacker authenticated as at least

    newswww.securityweek.comJul 17, 2026, 7:15 AM
  • bilities in the Fortinet FortiSandbox threat detection platform. These two critical-severity security flaws (tracked as CVE-2026-39808 and CVE-2026-25089 ) were addressed by Fortinet on April 14 and June 9, respectively. As the company detailed in security advisories issued at the time, successful exploitation allows unauthenticated threat actors to ex

    newswww.bleepingcomputer.comJul 17, 2026, 7:03 AM
  • ee new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability These

    governmentwww.cisa.govJul 16, 2026, 12:00 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: A hardware neural network backdoor that hides in plain sight Deep learning systems on edge devices often rely on third-party-designed FPGAs and ASICs for performance and efficiency, creating supply chain risks. Researchers from the University of Tennessee and the University of Florida developed HAMLOCK, a backdoor attack that splits malicious functionality between hardware and software, making detection more difficult. Onspring … More →

    newswww.helpnetsecurity.comJun 21, 2026, 8:00 AM
  • SOCRadar has detected 30,000 compromised Fortinet firewalls that expose networks to hacking.

    newswww.securityweek.comJun 17, 2026, 6:53 AM
  • Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from threat intelligence company Defused, which said that the exploit for one of the flaws is vibecoded, and likely faulty. The vulnerabilities Fortinet disclosed CVE-2026-39813 and CVE-2026-39808 in April 2026. The former is a path traversal vulnerability in … More →

    newswww.helpnetsecurity.comJun 16, 2026, 3:27 PM
  • Three FortiSandbox flaws, including one patched last week, are being actively exploited, highlighting the shrinking window for defenders. Cybersecurity firm Defused Cyber confirmed it’s seen active exploitation of three vulnerabilities in Fortinet FortiSandbox within a 24-hour window. Two of them had patches sitting available since April. The third got fixed last week, which, apparently, wasn’t […]

    newssecurityaffairs.comJun 16, 2026, 2:21 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Bringing governance and visibility to machine and AI identities In this Help Net Security interview, Archit Lohokare, CEO of AppViewX, explains how the rise of AI marked a turning point where machine and AI agent identities began converging into a single problem. Drawing on his experience across IBM and CyberArk, he describes the shift from human-driven systems to autonomous machines. … More →

    newswww.helpnetsecurity.comApr 19, 2026, 8:00 AM
  • Two vulnerabilities (CVE-2026-39813, CVE-2026-39808) in FortiSandbox could be leveraged by unauthenticated attackers to bypass authentication and execute unauthorized code or commands on vulnerable systems. Both vulnerabilities can be triggered with a specially crafted HTTP request, putting unpatched FortiSandbox deployments at risk. About FortiSandbox FortiSandbox is Fortinet’s security solution for detecting and analyzing advanced threats. It does so by detonating suspicious files and URLs in an isolated environment and returning verdicts. Other Fortinet products – firewalls, … More →

    newswww.helpnetsecurity.comApr 16, 2026, 12:48 PM
  • The flaws could allow attackers to bypass authentication or execute arbitrary code or commands via HTTP requests.

    newswww.securityweek.comApr 15, 2026, 9:37 AM
  • No excerpt available.

    Mitigationwww.cisa.govApr 14, 2026, 4:16 PM
  • No excerpt available.

    Exploitgithub.comApr 14, 2026, 4:16 PM
  • https://fortiguard.fortinet.com/psirt/FG-IR-26-100fortiguard.fortinet.com

    No excerpt available.

    Vendor Advisoryfortiguard.fortinet.comApr 14, 2026, 4:16 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

2 repository references · best confidence 0.90 · max 0 stars
  • githubNVD Exploit reference0 starsDiscovered Jul 16, 2026, 9:10 PM

    NVD labels the source link as Exploit; this is not independent verification of the repository's code.

  • gitlabDiscovery source unavailable0 starsDiscovered Jul 9, 2026, 6:51 PM

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence