CVE Tools

Critical Fortinet FortiSandbox flaws now exploited in attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedFortiSandbox

Our summary

Threat actors are reportedly exploiting multiple critical Fortinet FortiSandbox vulnerabilities in the wild, enabling privilege escalation and remote code execution without authentication or user interaction. The affected flaws are tracked as CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, and Fortinet released security updates on April 14—organizations should upgrade to the latest fixed versions to stop active attacks. This matters because FortiSandbox weaknesses have previously been leveraged in ransomware and intrusion campaigns to break into target networks.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store