CVE-2026-39808
published 2026-04-14CVE-2026-39808: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-07-19
Exploited in the wild
EPSS
89.69%
99.8th percentile
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | 4.4.0 – 4.4.9 | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url/fortisandbox/job-detail/tracer-behavior?jid=%7c%28echo+{{string}}+%3e+%2fweb%2fng%2f{{filename}}.txt%29%7c↗
- →Exploit targets the `jid` parameter of the `/fortisandbox/job-detail/tracer-behavior` API endpoint via pipe-encoded OS command injection (`%7c` = `|`). Monitor HTTP GET requests to this path containing pipe characters (`|`, URL-encoded as `%7c`) in the `jid` query parameter. ↗
- →The exploit writes arbitrary files to `/web/ng/` on the FortiSandbox filesystem and then retrieves them via `/ng/<filename>.txt`. Detect two-stage exploitation: an anomalous GET to the tracer-behavior endpoint followed by a GET to `/ng/*.txt` returning HTTP 200. ↗
- →Vulnerability is exploitable by unauthenticated attackers via crafted HTTP requests — no credentials required. Prioritize perimeter-facing FortiSandbox instances for detection and blocking. ↗
- →Active in-the-wild exploitation confirmed alongside CVE-2026-39813 and CVE-2026-25089. Treat any FortiSandbox alert for this CVE as part of a potential multi-CVE attack chain. ↗
- →Nuclei template uses two sequential HTTP requests as a probe: (1) inject command via `jid` parameter to write a file, (2) verify file contents via `/ng/<filename>.txt`. A 200 response containing the injected string confirms RCE. Use this two-request pattern in IDS/WAF signatures. ↗
- ·Affected versions are FortiSandbox 4.4.0 through 4.4.8 only. Version 4.4.9 and later are patched. Confirm exact version before applying detection rules to avoid false positives on patched systems. ↗
- ·The vulnerability is in the JRPC/API endpoint (`/fortisandbox/job-detail/tracer-behavior`). Ensure WAF/IDS rules cover both URL-encoded (`%7c`) and decoded (`|`) pipe characters in the `jid` parameter. ↗
- ·CISA KEV remediation due date is 2026-07-19. Reference vendor advisory FG-IR-26-100 for authoritative patch guidance. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Fortinet FortiSandbox/FortiSandbox PaaS up to 4.4.8 os command injection (FG-IR-26-100 / WID-SEC-2026-1094)
vuldb·2026-07-17·CVSS 9.8
CVE-2026-39808 [CRITICAL] Fortinet FortiSandbox/FortiSandbox PaaS up to 4.4.8 os command injection (FG-IR-26-100 / WID-SEC-2026-1094)
A vulnerability marked as critical has been reported in Fortinet FortiSandbox and FortiSandbox PaaS up to 4.4.8. This issue affects some unknown processing. This manipulation causes os command injection.
This vulnerability is handled as CVE-2026-39808. The attack can be initiated remotely. Additionally, an exploit exists.
It is suggested to upgrade the affected component.
GHSA
GHSA-wfjv-vrx5-2cf2: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4
ghsa_unreviewed·2026-04-14
CVE-2026-39808 [CRITICAL] CWE-78 GHSA-wfjv-vrx5-2cf2: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via
VulnCheck
Fortinet fortisandbox Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2026·CVSS 9.8
CVE-2026-39808 [CRITICAL] Fortinet fortisandbox Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Fortinet fortisandbox Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via
Affected: Fortinet fortisandbox
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://api.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-39808&date=2026-06-09
Exploit PoC: https://vulncheck.com/xdb/baecd56da872; https://vulncheck.com/xdb/50e019aa766f
CISA
Fortinet FortiSandbox OS Command Injection Vulnerability
cisa·2026-07-16·CVSS 9.8
CVE-2026-39808 [CRITICAL] CWE-78 Fortinet FortiSandbox OS Command Injection Vulnerability
Vulnerability: Fortinet FortiSandbox OS Command Injection Vulnerability
Affected: Fortinet FortiSandbox
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Notes
Fortinet
OS Command Injection through API endpoint
vendor_fortinet·2026-04-14·CVSS 9.8
CVE-2026-39808 [CRITICAL] CWE-78 OS Command Injection through API endpoint
FG-IR-26-100: OS Command Injection through API endpoint
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via
CVEs: CVE-2026-39808
CWEs: CWE-78
CVSS: 9.8 (critical)
Affected products: FortiSandbox, Fortinet
No detection rules found.
Nuclei
Fortinet FortiSandbox - Command Injection
nuclei·CVSS 9.8
CVE-2026-39808 [CRITICAL] Fortinet FortiSandbox - Command Injection
Fortinet FortiSandbox - Command Injection
Fortinet FortiSandbox 4.4.0 through 4.4.8 contains a command injection caused by improper neutralization of special elements in OS commands, letting attackers execute unauthorized code or commands, exploit requires crafted input.
Template:
id: CVE-2026-39808
info:
name: Fortinet FortiSandbox - Command Injection
author: DhiyaneshDk
severity: critical
description: |
Fortinet FortiSandbox 4.4.0 through 4.4.8 contains a command injection caused by improper neutralization of special elements in OS commands, letting attackers execute unauthorized code or commands, exploit requires crafted input.
impact: |
Attackers can execute arbitrary code or commands, potentially leading to full system compromise.
remediation: Upgrade FortiSandbox to version 4.4.9
Hackernews
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
blogs_hackernews·2026-07-17·CVSS 6.5
CVE-2026-58644 [MEDIUM] CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.
The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute arbitrary code.
"In a network-based attack, an attacker authenticated as at least a Sit
Checkpoint
22nd June – Threat Intelligence Report
blogs_checkpoint·2026-06-22
CVE-2026-42824 22nd June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 22nd June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident exposed driver’s license information, passport numbers, emails, phone numbers, and residential addresses for 3,087,721 hunting and fishing license customers. Social Security numbers and payment dat
Bleepingcomputer
Critical Fortinet FortiSandbox flaws now exploited in attacks
blogs_bleepingcomputer·2026-06-16·CVSS 6.5
CVE-2026-39813 [MEDIUM] Critical Fortinet FortiSandbox flaws now exploited in attacks
## Critical Fortinet FortiSandbox flaws now exploited in attacks
## Sergiu Gatlan
Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused.
Fortinet released security updates for these three critical-severity security flaws (tracked as CVE-2026-39813 , CVE-2026-39808 , and CVE-2026-25089 ) on April 14.
These flaws allow unauthenticated threat actors to escalate privileges and execute unauthorized code remotely through low-complexity command injection attacks that require no user interaction. To resolve these issues and block incoming attacks, admins must upgrade affected deployments to the latest released versions.
"We are observing exploitation of multiple Fortinet FortiS
Hackernews
Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
blogs_hackernews·2026-06-16·CVSS 9.8
CVE-2026-39813 [CRITICAL] Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber.
In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808 , and CVE-2026-25089 over the past 24 hours.
CVE-2026-39813 (CVSS score: 9.1) refers to a path traversal vulnerability in FortiSandbox JRPC API that could allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests.
The second flaw, CVE-2026-39808 (CVSS score: 9.1), is a case o
Hackernews
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
blogs_hackernews·2026-04-20
CVE-2026-20184 ⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
Monday’s recap shows the same pattern in different places. A third-party tool becomes a way in, then leads to internal access. A trusted download path is briefly swapped to deliver malware. Browser extensions act normally while pulling data and running code. Even update channels are used to push payloads. It’s not breaking systems—it’s bending trust.
There’s also a shift in how attacks run. Slower check-ins, multi-stage payloads, andmore code kept in memory. Attackers lean on real tools and normal workflows instead of custom builds. Some cas
Hackernews
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
blogs_hackernews·2026-04-15·CVSS 9.9
[CRITICAL] April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases.
Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse ( CVE-2026-27681 , CVSS score: 9.9) that could result in the execution of arbitrary database commands.
"The vulnerable ABAP program allows a low-privileged user to upload a file with arbitrary SQL statements that will then be executed," Onapsis said in an a
2026-04-14
Published
2026-07-16
Added to CISA KEV
Exploited in the wild