Critical Fortinet FortiSandbox flaws now exploited in attacks
Reported exploitedFortiSandboxOur summary
Threat actors are reportedly exploiting multiple critical Fortinet FortiSandbox vulnerabilities in the wild, enabling privilege escalation and remote code execution without authentication or user interaction. The affected flaws are tracked as CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, and Fortinet released security updates on April 14—organizations should upgrade to the latest fixed versions to stop active attacks. This matters because FortiSandbox weaknesses have previously been leveraged in ransomware and intrusion campaigns to break into target networks.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.