CISA Confirms Active Exploitation of Two Fortinet FortiSandbox Flaws
CISA has confirmed active exploitation of two Fortinet FortiSandbox vulnerabilities and added both to its Known Exploited Vulnerabilities catalogue, with the federal remediation deadline already passed.

Network security appliance representing an actively exploited malware sandboxing tool
The US Cybersecurity and Infrastructure Security Agency has confirmed active exploitation of two vulnerabilities in Fortinet's FortiSandbox product line, adding both to its Known Exploited Vulnerabilities catalogue on 16 July.
Two flaws sharing the same root cause
CVE-2026-39808 and CVE-2026-25089 are both OS command injection vulnerabilities, arising when an application fails to sanitise user supplied input before passing it to system level commands. CVE-2026-39808 affects on-premises FortiSandbox appliances and lets an unauthenticated attacker execute unauthorised code or commands by sending specially crafted HTTP requests. CVE-2026-25089 has a broader footprint, affecting not just on-premises deployments but also FortiSandbox Cloud and FortiSandbox PaaS, through the same unauthenticated command execution path. Neither flaw requires valid credentials, which significantly lowers the barrier for exploitation against any internet facing instance.
Why this specific product matters
FortiSandbox is a malware analysis and threat detection appliance, commonly deployed across finance, healthcare, and critical infrastructure sectors to inspect suspicious files and network traffic before they reach production systems. A successful compromise does not just expose the appliance itself, it gives an attacker a foothold inside an organisation's security monitoring infrastructure, with the potential to undermine detection capability while enabling lateral movement deeper into the network. This is a case where the security tool becomes the attack surface, the same underlying risk we flagged in our coverage of the SonicWall SMA 1000 zero-days, where the compromised device sat directly at the boundary meant to protect everything behind it.
The deadline has already passed
Under Binding Operational Directive 26-04, US federal civilian agencies were required to apply patches or mitigations by 19 July. That deadline has now passed. While the directive legally binds only federal agencies, CISA is urging all organisations running FortiSandbox, in any sector and any region, to treat this as an immediate patching priority rather than a routine update. For GCC organisations running FortiSandbox, particularly in finance and critical infrastructure where this appliance is commonly deployed, a missed CISA deadline is a useful, if informal, signal of how urgently this needs to move up the queue, echoing the same pattern we saw with Microsoft's record-setting Patch Tuesday release, which shipped with two zero-days already under active attack. CISA has not confirmed whether either flaw has been used in ransomware campaigns, listing that status as unknown for both entries, but inclusion in the KEV catalogue on its own confirms exploitation is happening, regardless of what the end objective turns out to be.
What to do
Organisations should apply Fortinet's vendor issued patches or mitigations immediately, prioritising any internet facing FortiSandbox instance given the unauthenticated nature of both exploits. Where immediate patching is not possible, network isolation of exposed instances should be treated as an interim control. CISA also directs organisations assessing potentially compromised systems to consult its Forensics Triage Requirements to ensure evidence is properly preserved before remediation begins, since a security appliance that has itself been compromised may hold evidence relevant to understanding what else in the environment was touched.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.