Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-39808

Published 2026-04-14
Updated 2 months ago
Vendor/s
Fortinet
Product/s
FortiSandbox
Version/s
4.4.0 > 4.4.9
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

Critical CVSS 9.8 OS command injection vulnerability in Fortinet FortiSandbox (4.4.0-4.4.9) allows remote code execution. Actively exploited in the wild.

CPE

Fortinet logo
Fortinet
Product Version Start Version End (excl.) Status
fortisandbox 4.4.0 4.4.9 vulnerable

Related weakness (CWE)

CWE-78

Remediation plan

1

Apply official patches

Immediately download and install the latest firmware updates from the Fortinet Support Portal that specifically address the FG-IR-26-100 advisory.

2

Update affected systems

Ensure all FortiSandbox deployments running versions 4.4.0 through 4.4.9 are upgraded to version 4.4.10 or the latest available stable release to eliminate the vulnerable code path.

3

Restrict access

Minimize the attack surface by placing FortiSandbox management interfaces behind a VPN or hardware firewall and restricting network access to known, trusted administrative IP addresses.

4

Monitor for exploitation

Perform a forensic triage of system logs for unusual shell command execution or unauthorized administrative access, adhering to CISA’s Forensics Triage Requirements and BOD 26-04 guidance.

Detection Guidance

Detection should focus on identifying unusual OS command execution patterns within FortiSandbox system logs. Monitor for unexpected outbound network connections originating from the appliance, which may indicate a reverse shell or data exfiltration. Additionally, inspect web server and API logs for suspicious payloads containing shell metacharacters such as semicolons, pipes, or backticks. Security teams should also audit administrative account logs for unauthorized logins or the creation of new, unrecognized local users.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management