Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet FortiSandbox Vulnerabilities Under Attack

Fortinet FortiSandbox Vulnerabilities Under Attack

Posted on June 16, 2026 By CWS

Recent Exploitation of Fortinet FortiSandbox Vulnerabilities

Threat intelligence firm Defused Cyber has reported that malicious actors are currently exploiting several vulnerabilities in Fortinet FortiSandbox. These include CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, all of which pose significant security risks.

Details of the Vulnerabilities

CVE-2026-39813 is a critical path traversal flaw in the FortiSandbox JRPC API. Rated with a CVSS score of 9.1, this vulnerability enables attackers to bypass authentication using specially crafted HTTP requests. Similarly, CVE-2026-39808, also with a CVSS score of 9.1, allows unauthorized execution of commands through operating system command injection. Both vulnerabilities received patches from Fortinet in April 2026.

The third vulnerability, CVE-2026-25089, was addressed last week. It also involves operating system command injection, impacting FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS Web UI. This vulnerability can lead to unauthorized command execution, and Defused Cyber highlighted that its exploit appears to be AI-generated, albeit with errors. Importantly, a fully functional exploit has not been publicly shared.

Context and Implications

Fortinet devices have increasingly become targets for cyber attackers. Earlier in April 2026, Fortinet had to issue emergency patches for a critical flaw in FortiClient EMS, identified as CVE-2026-35616. This vulnerability, also with a CVSS score of 9.1, had been actively exploited in cyber attacks.

Future Outlook and Recommendations

The continuous targeting of Fortinet products underscores the need for organizations to remain vigilant and promptly apply security patches. Businesses utilizing Fortinet solutions should ensure they are up-to-date with the latest security updates to mitigate potential risks. As cyber threats evolve, staying informed and prepared is crucial to safeguarding sensitive data and infrastructure.

The Hacker News Tags:AI model, CVE-2026-25089, CVE-2026-39808, CVE-2026-39813, Cybersecurity, Exploits, Fortinet, FortiSandbox, Patches, security vulnerabilities, threat intelligence

Post navigation

Previous Post: Critical Cisco SD-WAN Flaw Exploited in Zero-Day Attacks
Next Post: Cybersecurity Leaders Request Easing of AI Model Restrictions

Related Posts

Chrome 0-Day, AI Hacking Tools, DDR5 Bit-Flips, npm Worm & More Chrome 0-Day, AI Hacking Tools, DDR5 Bit-Flips, npm Worm & More The Hacker News
HPE Issues Security Patch for StoreOnce Bug Allowing Remote Authentication Bypass HPE Issues Security Patch for StoreOnce Bug Allowing Remote Authentication Bypass The Hacker News
Critical Drupal Flaw Threatens PostgreSQL Sites with RCE Critical Drupal Flaw Threatens PostgreSQL Sites with RCE The Hacker News
Critical cPanel Vulnerability Allows Root Access Critical cPanel Vulnerability Allows Root Access The Hacker News
CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms The Hacker News
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack
  • New DDRop Attack Targets Intel and AMD Confidential Computing
  • Twitch Extension JeetBot Risks User Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack
  • New DDRop Attack Targets Intel and AMD Confidential Computing
  • Twitch Extension JeetBot Risks User Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark