Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerabilities in FortiSandbox Under Exploitation

Critical Vulnerabilities in FortiSandbox Under Exploitation

Posted on June 16, 2026 By CWS

Recent cyber threats have put Fortinet’s FortiSandbox platform in the spotlight, as multiple critical vulnerabilities are currently being exploited by threat actors. Over the past 24 hours, live attack telemetry has confirmed these attempts, raising significant security concerns.

Identification of Critical CVEs

Security firm Defused has identified three critical Common Vulnerabilities and Exposures (CVEs) that are being actively targeted. Notably, CVE-2026-39813, which had no prior exploitation history, is now under attack. Honeypot sensors have intercepted attempts to exploit these vulnerabilities through port 443, specifically targeting the /jsonrpc/ API endpoint.

Among these, CVE-2026-39813 is a path traversal flaw in the FortiSandbox JRPC API, allowing unauthenticated attackers to bypass security measures via crafted HTTP requests. This vulnerability enables access to sensitive data without credentials, marking a significant first in observed attacks.

Details of Vulnerable Endpoints

CVE-2026-39808 is another critical flaw, categorized as an OS command injection vulnerability. It enables attackers to execute arbitrary commands as root through an API endpoint. Although a proof-of-concept exploit has been public since April 2026, recent attacks have utilized this method, indicating its effectiveness.

The third vulnerability, CVE-2026-25089, shares similar characteristics with an OS command injection flaw affecting multiple FortiSandbox versions and cloud deployments. Despite no public exploit being available, opportunistic attacks suggest attempts to exploit weaknesses through AI-assisted or heuristic methods.

Implications for Network Security

The affected FortiSandbox versions can be exploited without any authentication, posing a significant risk to exposed management interfaces. A compromised system could potentially validate malicious files as safe or allow attackers to move laterally within networks, threatening broader enterprise security.

Analysis of attack patterns shows the exploit source, identified as IP address 141.11.43.175, linked to AS136510 Streamline Servers Pty Ltd in Singapore. This entity carries a high threat score, emphasizing the importance of monitoring for indicators of compromise, such as specific user-agents and targeted endpoints.

The cybersecurity community is urged to stay updated on further developments and apply necessary patches to mitigate these threats. Continuous vigilance and proactive defense strategies remain crucial in countering such sophisticated cyber threats.

Cyber Security News Tags:API security, command injection, CVE, Cybersecurity, enterprise security, Exploitation, Fortinet, FortiSandbox, honeypot sensors, indicators of compromise, network security, path traversal, Threat Actors, Vulnerabilities, zero-day exploit

Post navigation

Previous Post: TrustCloud Introduces Automated Solution for CISO Application Assurance
Next Post: ClickFix Campaigns Enhance Malware Tactics with New Loaders

Related Posts

New VanHelsing Ransomware RaaS Model Attacking Windows, Linux, BSD, ARM, and ESXi Systems New VanHelsing Ransomware RaaS Model Attacking Windows, Linux, BSD, ARM, and ESXi Systems Cyber Security News
WhatsApp Crypt Tool to Encrypt and Decrypt WhatsApp Backups WhatsApp Crypt Tool to Encrypt and Decrypt WhatsApp Backups Cyber Security News
Microsoft Unveils European Security Initiative to Target Cybercriminal Networks Microsoft Unveils European Security Initiative to Target Cybercriminal Networks Cyber Security News
Cisco Secure Firewall Snort 3 Detection Engine Vulnerability Enables DoS Attacks Cisco Secure Firewall Snort 3 Detection Engine Vulnerability Enables DoS Attacks Cyber Security News
Hackers Infiltrate VS Code Marketplace with 19 Malicious Extensions Posing as PNG File Hackers Infiltrate VS Code Marketplace with 19 Malicious Extensions Posing as PNG File Cyber Security News
Massive Spike in Password Attacks Targeting Cisco ASA VPN Followed by Microsoft 365 Massive Spike in Password Attacks Targeting Cisco ASA VPN Followed by Microsoft 365 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Microsoft Teams to Mask Ransomware Traffic
  • Arch Linux Halts AUR Signups Amid Major Supply Chain Threat
  • Google Cloud Vertex AI SDK Flaw Exposed Model Uploads
  • Aembit Enhances IAM for Microsoft’s Copilot Studio
  • Cal Water Probes Alleged Iranian Hacker Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Microsoft Teams to Mask Ransomware Traffic
  • Arch Linux Halts AUR Signups Amid Major Supply Chain Threat
  • Google Cloud Vertex AI SDK Flaw Exposed Model Uploads
  • Aembit Enhances IAM for Microsoft’s Copilot Studio
  • Cal Water Probes Alleged Iranian Hacker Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark