CVE-2026-39808
Fortinet FortiSandbox, FortiSandbox PaaS, fortisandbox
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
- CVSS
- 9.8
- EPSS
- 89.7% 99.8% percentile
- CISA KEV
- Listed
- Published
- 2026.04.15