Security bulletin with exclamation point symbol in the middle of the screen
Security bulletin with exclamation point symbol in the middle of the screen

CVE-2026-39808: Critical Fortinet FortiSandbox OS Command Injection Vulnerability

CRITICAL: Fortinet FortiSandbox CVE-2026-39808 OS command injection (CVSS 9.8) actively exploited. Public PoC available. Upgrade to 4.4.9+. Federal agencies: BOD 26-04 mandate applies.
Security bulletin with exclamation point symbol in the middle of the screen
6 min read

Threat Summary

On April 14, 2026, Fortinet released fixes for a critical OS command injection vulnerability in FortiSandbox, tracked as CVE-2026-39808. The flaw allows remote attackers to execute arbitrary operating system commands via crafted HTTP requests. Fortinet rates CVE-2026-39808 at CVSS 9.8 (as submitted to NVD). CISA lists CVE-2026-39808 as known exploited in the wild, and public proof of concept (PoC) exploit code is available on GitHub demonstrating remote command execution against affected versions.

Given the severity and remote attack surface, further and opportunistic exploitation is likely until patches are applied. CISA’s BOD 26-04 also directs federal agencies to prioritize remediation of KEV-listed vulnerabilities.

Recommendations for CVE-2026-39808

  • Prioritize patching Fortinet FortiSandbox systems.
  • Upgrade FortiSandbox to version 4.4.9 or later, as provided in Fortinet PSIRT advisory FG-IR-26-100.
  • FortiSandbox PaaS versions prior to 5.0 are also affected. PaaS customers running version 5.0 require no action.
  • If immediate patching is not possible: remove any public internet exposure to FortiSandbox HTTP/HTTPS interfaces and restrict management access to a VPN or allowlisted admin subnets.
  • Consider temporary virtual patching via a WAF or reverse proxy to block common OS command injection patterns while patching is underway.
  • Increase monitoring of FortiSandbox access and system logs for anomalies until remediation is complete.
  • Refer to the Fortinet advisory (FG-IR-26-100) for the complete list of affected products and specific patch versions:
  • Please follow your organization’s patching and testing guidelines to minimize potential operational impact.

Temporary Workarounds

No vendor-provided workarounds have been identified. See Recommendations for interim risk-reduction steps.

References:

Share this post: