Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerabilities in FortiSandbox Under Exploitation

Critical Vulnerabilities in FortiSandbox Under Exploitation

Posted on June 16, 2026 By CWS

Recent cyber threats have put Fortinet’s FortiSandbox platform in the spotlight, as multiple critical vulnerabilities are currently being exploited by threat actors. Over the past 24 hours, live attack telemetry has confirmed these attempts, raising significant security concerns.

Identification of Critical CVEs

Security firm Defused has identified three critical Common Vulnerabilities and Exposures (CVEs) that are being actively targeted. Notably, CVE-2026-39813, which had no prior exploitation history, is now under attack. Honeypot sensors have intercepted attempts to exploit these vulnerabilities through port 443, specifically targeting the /jsonrpc/ API endpoint.

Among these, CVE-2026-39813 is a path traversal flaw in the FortiSandbox JRPC API, allowing unauthenticated attackers to bypass security measures via crafted HTTP requests. This vulnerability enables access to sensitive data without credentials, marking a significant first in observed attacks.

Details of Vulnerable Endpoints

CVE-2026-39808 is another critical flaw, categorized as an OS command injection vulnerability. It enables attackers to execute arbitrary commands as root through an API endpoint. Although a proof-of-concept exploit has been public since April 2026, recent attacks have utilized this method, indicating its effectiveness.

The third vulnerability, CVE-2026-25089, shares similar characteristics with an OS command injection flaw affecting multiple FortiSandbox versions and cloud deployments. Despite no public exploit being available, opportunistic attacks suggest attempts to exploit weaknesses through AI-assisted or heuristic methods.

Implications for Network Security

The affected FortiSandbox versions can be exploited without any authentication, posing a significant risk to exposed management interfaces. A compromised system could potentially validate malicious files as safe or allow attackers to move laterally within networks, threatening broader enterprise security.

Analysis of attack patterns shows the exploit source, identified as IP address 141.11.43.175, linked to AS136510 Streamline Servers Pty Ltd in Singapore. This entity carries a high threat score, emphasizing the importance of monitoring for indicators of compromise, such as specific user-agents and targeted endpoints.

The cybersecurity community is urged to stay updated on further developments and apply necessary patches to mitigate these threats. Continuous vigilance and proactive defense strategies remain crucial in countering such sophisticated cyber threats.

Cyber Security News Tags:API security, command injection, CVE, Cybersecurity, enterprise security, Exploitation, Fortinet, FortiSandbox, honeypot sensors, indicators of compromise, network security, path traversal, Threat Actors, Vulnerabilities, zero-day exploit

Post navigation

Previous Post: TrustCloud Introduces Automated Solution for CISO Application Assurance
Next Post: ClickFix Campaigns Enhance Malware Tactics with New Loaders

Related Posts

BlueNoroff Hackers Weaponize Zoom App to Attack System Using Infostealer Malware BlueNoroff Hackers Weaponize Zoom App to Attack System Using Infostealer Malware Cyber Security News
Hackers Using Generative AI ‘ChatGPT’ to Evade Anti-virus Defenses Hackers Using Generative AI ‘ChatGPT’ to Evade Anti-virus Defenses Cyber Security News
Phishing Campaign Targets Users with Fake Event Invites Phishing Campaign Targets Users with Fake Event Invites Cyber Security News
Hackers Target Cisco Devices with Known Vulnerabilities Hackers Target Cisco Devices with Known Vulnerabilities Cyber Security News
iOS 26 Deletes Pegasus and Predator Spyware Infection Evidence by Overwriting The ‘shutdown.log’ file on Reboot iOS 26 Deletes Pegasus and Predator Spyware Infection Evidence by Overwriting The ‘shutdown.log’ file on Reboot Cyber Security News
1-Click Clawdbot Vulnerability Enable Malicious Remote Code Execution Attacks 1-Click Clawdbot Vulnerability Enable Malicious Remote Code Execution Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top Web Application Firewalls for 2026: Expert Ranking
  • Top DNS Security Solutions for 2026
  • Windows 11 Enhances Taskbar and AI Features
  • Top Cloud Firewall Solutions for 2026: A Comprehensive Guide
  • Balance Theory Secures $19M for Cybersecurity Investment Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top Web Application Firewalls for 2026: Expert Ranking
  • Top DNS Security Solutions for 2026
  • Windows 11 Enhances Taskbar and AI Features
  • Top Cloud Firewall Solutions for 2026: A Comprehensive Guide
  • Balance Theory Secures $19M for Cybersecurity Investment Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark