Skip to content
All vulnerabilities
CVE-2026-39808KEV

Fortinet FortiSandbox OS Command Injection Vulnerability

Severity
Critical9.8CVSS 3.1, Critical
Known exploited
Known exploitedFederal remediation due date: 19 Jul 2026
Exploit prediction
47%
Published
14 Apr 2026Updated 17 Jul 2026 · Last verified 30 Sept 2026

Known remediation

Fixed releases per branch, as the vendor states them. Patcharo never infers a fix.

Workaround / Vendor remediation

Vendor remediation · FortiSandbox

Upgrade to FortiSandbox version 4.4.9 or above Upgrade to FortiSandbox PaaS version 5.0.2 or above

Description

Title, description and vendor guidance are quoted from the source records.

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Weakness: CWE-78

Known exploited

Added to CISA KEV on 16 Jul 2026

Federal remediation due date: 19 Jul 2026

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Exploit prediction

47% probability of exploitation in the next 30 days (percentile 99%).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the source states, per branch

Versions matched by Patcharo

Fortinet FortiSandboxSource: Fortinet (CVE record)

BranchAffectedFixed in
4.4
4.4.0 – 4.4.8
Fixed after 4.4.8

Versions not listed are stated unaffected by the vendor.

Affected products

  • Fortinet FortiSandbox PaaS · 23.4.4374, 23.4.4350, 23.3.4329, 23.1.4245, 22.2.4151, 22.2.4134, 22.1.4113, 21.4.4072, 21.3.4055

References

Provenance

Every fact on this page comes from the sources below. Nothing is written by an AI.

Fortinet (CVE record)
Fortinet (CVE record) · 30 Sept 2026 at 00:17 UTC · Parser patcharo-cve5/1.1.0
CISA Known Exploited Vulnerabilities
CISA Known Exploited Vulnerabilities · 30 Sept 2026 at 00:17 UTC · Parser patcharo-kev/1.0.0
NVD
NVD · 28 Sept 2026 at 07:02 UTC · Parser patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 30 Sept 2026 at 00:17 UTC · Parser patcharo-epss/1.0.0

Last verified: 30 Sept 2026 at 00:17 UTC