CVE detail
CVE-2026-39808
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 28.3 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 8.5
Why it matters now
Mention timeline
- Total mentions
- 6
- within the 30d window
- Peak daily
- 4
- highest bucket
Evidence
Source links by recency
16 source links · newest first
- U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
CISA) added Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities (KEV) catalog . CVE-2026-25089 (CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-39808 (CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-58644 (CVSS score of 9.8) Microsoft Share
newssecurityaffairs.comJul 18, 2026, 11:49 AM - Attackers target critical FortiSandbox flaws as CISA issues patch orderThe Register Security
endars after CISA confirmed a pair of critical FortiSandbox bugs are being actively exploited. The two bugs, tracked as CVE-2026-39808 and CVE-2026-25089, both carry CVSS scores of 9.1 and affect FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. According to Fortinet, they are OS command injection flaws that allow unauthenticated attackers to ex
newswww.theregister.comJul 17, 2026, 11:58 AM - CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet VulnerabilitiesInfosecurity Magazine
in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) has warned. The vulnerabilities, tracked as CVE-2026-39808 and CVE-2026-25089 are both critical, with a severity rating (CVSS) of 9.1 each. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog on July 16, suggesting evidence of observed exploitation in the wild.
newswww.infosecurity-magazine.comJul 17, 2026, 9:45 AM y remote code execution (RCE) vulnerability in Microsoft SharePoint, the US cybersecurity agency CISA warns. Tracked as CVE-2026-58644 (CVSS score of 9.8) and fixed as part of Microsoft’s July 2026 Patch Tuesday updates, the flaw is described as a deserialization of untrusted data issue. “In a network-based attack, an attacker authenticated as at least
newswww.securityweek.comJul 17, 2026, 7:15 AM- CISA urges immediate action on actively exploited Fortinet flawsBleepingComputer
bilities in the Fortinet FortiSandbox threat detection platform. These two critical-severity security flaws (tracked as CVE-2026-39808 and CVE-2026-25089 ) were addressed by Fortinet on April 14 and June 9, respectively. As the company detailed in security advisories issued at the time, successful exploitation allows unauthenticated threat actors to ex
newswww.bleepingcomputer.comJul 17, 2026, 7:03 AM ee new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability These
governmentwww.cisa.govJul 16, 2026, 12:00 PM- Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attackHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: A hardware neural network backdoor that hides in plain sight Deep learning systems on edge devices often rely on third-party-designed FPGAs and ASICs for performance and efficiency, creating supply chain risks. Researchers from the University of Tennessee and the University of Florida developed HAMLOCK, a backdoor attack that splits malicious functionality between hardware and software, making detection more difficult. Onspring … More →
newswww.helpnetsecurity.comJun 21, 2026, 8:00 AM SOCRadar has detected 30,000 compromised Fortinet firewalls that expose networks to hacking.
newswww.securityweek.comJun 17, 2026, 6:53 AM- Attackers are exploiting FortiSandbox vulnerabilitiesHelp Net Security
Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from threat intelligence company Defused, which said that the exploit for one of the flaws is vibecoded, and likely faulty. The vulnerabilities Fortinet disclosed CVE-2026-39813 and CVE-2026-39808 in April 2026. The former is a path traversal vulnerability in … More →
newswww.helpnetsecurity.comJun 16, 2026, 3:27 PM Three FortiSandbox flaws, including one patched last week, are being actively exploited, highlighting the shrinking window for defenders. Cybersecurity firm Defused Cyber confirmed it’s seen active exploitation of three vulnerabilities in Fortinet FortiSandbox within a 24-hour window. Two of them had patches sitting available since April. The third got fixed last week, which, apparently, wasn’t […]
newssecurityaffairs.comJun 16, 2026, 2:21 PM- Week in review: Acrobat Reader flaw exploited, Claude Mythos offensive capabilities and limitsHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Bringing governance and visibility to machine and AI identities In this Help Net Security interview, Archit Lohokare, CEO of AppViewX, explains how the rise of AI marked a turning point where machine and AI agent identities began converging into a single problem. Drawing on his experience across IBM and CyberArk, he describes the shift from human-driven systems to autonomous machines. … More →
newswww.helpnetsecurity.comApr 19, 2026, 8:00 AM - Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808)Help Net Security
Two vulnerabilities (CVE-2026-39813, CVE-2026-39808) in FortiSandbox could be leveraged by unauthenticated attackers to bypass authentication and execute unauthorized code or commands on vulnerable systems. Both vulnerabilities can be triggered with a specially crafted HTTP request, putting unpatched FortiSandbox deployments at risk. About FortiSandbox FortiSandbox is Fortinet’s security solution for detecting and analyzing advanced threats. It does so by detonating suspicious files and URLs in an isolated environment and returning verdicts. Other Fortinet products – firewalls, … More →
newswww.helpnetsecurity.comApr 16, 2026, 12:48 PM The flaws could allow attackers to bypass authentication or execute arbitrary code or commands via HTTP requests.
newswww.securityweek.comApr 15, 2026, 9:37 AMNo excerpt available.
Mitigationwww.cisa.govApr 14, 2026, 4:16 PMNo excerpt available.
Exploitgithub.comApr 14, 2026, 4:16 PM- https://fortiguard.fortinet.com/psirt/FG-IR-26-100fortiguard.fortinet.com
No excerpt available.
Vendor Advisoryfortiguard.fortinet.comApr 14, 2026, 4:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
2 repository references · best confidence 0.90 · max 0 stars
- samu-delucas/CVE-2026-39808High confidencegithubNVD Exploit reference0 starsDiscovered Jul 16, 2026, 9:10 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
- error.inside/CVE-2026-39808Medium confidencegitlabDiscovery source unavailable0 starsDiscovered Jul 9, 2026, 6:51 PM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-25089CVSS 9.8 · Critical
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through…
- CVE-2025-53949CVSS 7.2 · High
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, Fo…
- CVE-2025-53679CVSS 7.2 · High
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, Fo…
- CVE-2024-54018CVSS 7.2 · High
Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthoriz…
- CVE-2024-52961CVSS 8.8 · High
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSa…
- CVE-2024-27778CVSS 8.8 · High
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through…