CISA KEV · Known exploitedCritical

CVE-2026-39808

Fortinet FortiSandbox, FortiSandbox PaaS, fortisandbox

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

CVSS
9.8
EPSS
89.7%
99.8% percentile
CISA KEV
Listed
Published
2026.04.15
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability89.7%
Technical severityCVSS 9.8

Vulnerability overview

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Affected product and versions

Product
Fortinet FortiSandbox, FortiSandbox PaaS, fortisandbox
Affected versions
>= 4.4.0 <= 4.4.8, >= 23.4.4374, >= 23.4.4350, >= 23.3.4329, >= 23.1.4245, >= 22.2.4151, >= 22.2.4134, >= 22.1.4113, >= 21.4.4072, >= 21.3.4055, >= 4.4.0 <= 4.4.9
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Due date: 2026.07.19
  1. 1
    Identify

    Confirm that Fortinet FortiSandbox, FortiSandbox PaaS, fortisandbox and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-78
KEV added
2026.07.16
Ransomware use
미확인