Critical Command‑Injection Flaws in FortiSandbox Added to CISA KEV Catalog
What It Is
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) placed two Fortinet FortiSandbox vulnerabilities (CVE‑2026‑39808 and CVE‑2026‑25089) into its Known Exploited Vulnerabilities (KEV) catalog. Both are OS‑command‑injection bugs that let an unauthenticated attacker run arbitrary commands via crafted HTTP requests against FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS.
Exploitability
- Active exploitation has been observed in the wild, with threat‑intel firm Defused reporting exploitation attempts in mid‑June.
- No public proof‑of‑concept has been released, but the presence of exploitation activity elevates risk.
- Both flaws are rated Critical (CVSS ≈ 9.8) and were patched by Fortinet in April (CVE‑2026‑39808) and June (CVE‑2026‑25089).
Affected Products
- FortiSandbox (on‑premises)
- FortiSandbox Cloud
- FortiSandbox PaaS
Why It Matters for Compliance & Audit Readiness
For SOC 2‑type organizations, FortiSandbox is a core component of the Security – Logical Access control family. An unpatched command‑injection flaw creates a direct path for attackers to bypass isolation, potentially exposing sensitive data and compromising the integrity of incident‑response evidence. Demonstrating timely patch management and evidence of remediation is a required control under the Vendor Management and Change Management criteria of the SOC 2 Trust Services Criteria. Failure to patch within the CISA deadline could be viewed as a lapse in due‑diligence, jeopardizing audit readiness.
Recommended Actions
- Verify that the April and June patches for CVE‑2026‑39808 and CVE‑2026‑25089 are applied across all FortiSandbox deployments.
- Update your Vendor‑Management control documentation to reflect the new patch status and retain patch‑installation logs as audit evidence.
- Conduct a focused vulnerability‑scan of any FortiSandbox instances to confirm remediation and to detect any residual exploitation artifacts.
- Review and tighten network‑segmentation rules around FortiSandbox to limit exposure of the “Start VNC” UI and other web‑based management interfaces.
- Incorporate the CISA KEV alert into your continuous monitoring playbook so future KEV additions trigger automatic remediation workflows.
Source: DataBreachToday – CISA Adds FortiSandbox Bugs to KEV Catalog