Critical Fortinet FortiSandbox flaws now exploited in attacks
Attackers are exploiting critical vulnerabilities in Fortinet's FortiSandbox platform. Fortinet released security updates for these flaws on April 14.
Intelligence analysis by Llama 3.3 70B

Several critical vulnerabilities in Fortinet's FortiSandbox are being exploited by attackers, allowing them to escalate privileges and execute unauthorized code remotely.
Imagine you have a special box that helps keep your computer safe from bad guys. But, there's a secret door in the box that the bad guys can open if they know the right code. That's kind of what's happening with some important computer security software right now. The bad guys have found the secret code and are using it to get into computers and cause trouble.
Analysis
The vulnerabilities in question, tracked as CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, are critical-severity security flaws that allow unauthenticated threat actors to escalate privileges and execute unauthorized code remotely through low-complexity command injection attacks. According to threat intelligence company Defused, attackers are now exploiting these vulnerabilities, with a working exploit for CVE-2026-25089 not yet publicly disclosed. Fortinet released security updates for these flaws on April 14, and admins must upgrade affected deployments to the latest released versions to resolve these issues and block incoming attacks. The exploitation of these vulnerabilities is particularly concerning, as Fortinet security flaws are often exploited in ransomware attacks and cyber espionage campaigns to breach targets' networks. In recent years, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has tracked 26 Fortinet vulnerabilities that have been exploited in attacks, 13 of which were abused by ransomware gangs. The active exploitation of these vulnerabilities highlights the importance of keeping software up to date and patching vulnerabilities in a timely manner to prevent attacks.
Key points
- Several critical vulnerabilities in Fortinet's FortiSandbox are being exploited by attackers
- The vulnerabilities allow unauthenticated threat actors to escalate privileges and execute unauthorized code remotely
- Fortinet released security updates for these flaws on April 14
- Admins must upgrade affected deployments to the latest released versions to prevent attacks
If admins upgrade their FortiSandbox deployments to the latest versions, they can prevent attackers from exploiting these vulnerabilities and protect their networks from breaches. Additionally, the fact that Fortinet has released security updates for these flaws shows that the company is taking steps to address the issue and prevent future attacks.
The exploitation of these vulnerabilities could lead to a significant increase in ransomware attacks and cyber espionage campaigns, as attackers take advantage of the flaws to breach targets' networks. Furthermore, the fact that a working exploit for CVE-2026-25089 has not yet been publicly disclosed suggests that attackers may be able to continue exploiting this vulnerability for some time, making it a significant threat to computer security.


