Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerabilities in FortiSandbox Under Exploitation

Critical Vulnerabilities in FortiSandbox Under Exploitation

Posted on June 16, 2026 By CWS

Recent cyber threats have put Fortinet’s FortiSandbox platform in the spotlight, as multiple critical vulnerabilities are currently being exploited by threat actors. Over the past 24 hours, live attack telemetry has confirmed these attempts, raising significant security concerns.

Identification of Critical CVEs

Security firm Defused has identified three critical Common Vulnerabilities and Exposures (CVEs) that are being actively targeted. Notably, CVE-2026-39813, which had no prior exploitation history, is now under attack. Honeypot sensors have intercepted attempts to exploit these vulnerabilities through port 443, specifically targeting the /jsonrpc/ API endpoint.

Among these, CVE-2026-39813 is a path traversal flaw in the FortiSandbox JRPC API, allowing unauthenticated attackers to bypass security measures via crafted HTTP requests. This vulnerability enables access to sensitive data without credentials, marking a significant first in observed attacks.

Details of Vulnerable Endpoints

CVE-2026-39808 is another critical flaw, categorized as an OS command injection vulnerability. It enables attackers to execute arbitrary commands as root through an API endpoint. Although a proof-of-concept exploit has been public since April 2026, recent attacks have utilized this method, indicating its effectiveness.

The third vulnerability, CVE-2026-25089, shares similar characteristics with an OS command injection flaw affecting multiple FortiSandbox versions and cloud deployments. Despite no public exploit being available, opportunistic attacks suggest attempts to exploit weaknesses through AI-assisted or heuristic methods.

Implications for Network Security

The affected FortiSandbox versions can be exploited without any authentication, posing a significant risk to exposed management interfaces. A compromised system could potentially validate malicious files as safe or allow attackers to move laterally within networks, threatening broader enterprise security.

Analysis of attack patterns shows the exploit source, identified as IP address 141.11.43.175, linked to AS136510 Streamline Servers Pty Ltd in Singapore. This entity carries a high threat score, emphasizing the importance of monitoring for indicators of compromise, such as specific user-agents and targeted endpoints.

The cybersecurity community is urged to stay updated on further developments and apply necessary patches to mitigate these threats. Continuous vigilance and proactive defense strategies remain crucial in countering such sophisticated cyber threats.

Cyber Security News Tags:API security, command injection, CVE, Cybersecurity, enterprise security, Exploitation, Fortinet, FortiSandbox, honeypot sensors, indicators of compromise, network security, path traversal, Threat Actors, Vulnerabilities, zero-day exploit

Post navigation

Previous Post: TrustCloud Introduces Automated Solution for CISO Application Assurance
Next Post: ClickFix Campaigns Enhance Malware Tactics with New Loaders

Related Posts

Apache Hadoop Vulnerability Exposes Systems Potential Crashes or Data Corruption Apache Hadoop Vulnerability Exposes Systems Potential Crashes or Data Corruption Cyber Security News
XLoader Malware Analyzed Using ChatGPT’s, Breaks RC4 Encryption Layers in Hours XLoader Malware Analyzed Using ChatGPT’s, Breaks RC4 Encryption Layers in Hours Cyber Security News
Malicious npm Packages as Utilities Let Attackers Destroy Production Systems Malicious npm Packages as Utilities Let Attackers Destroy Production Systems Cyber Security News
Critical AirDrop and Quick Share Flaws Expose Devices Critical AirDrop and Quick Share Flaws Expose Devices Cyber Security News
Fake Video Players Spread Malware: Crypto Miner and RAT Fake Video Players Spread Malware: Crypto Miner and RAT Cyber Security News
Microsoft Automates Windows 11 25H2 Upgrade Rollout Microsoft Automates Windows 11 25H2 Upgrade Rollout Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows 11 Enhances Taskbar and AI Features
  • Top Cloud Firewall Solutions for 2026: A Comprehensive Guide
  • Balance Theory Secures $19M for Cybersecurity Investment Platform
  • Critical Ruby on Rails Vulnerability Patched
  • Hackers Exploit Adform Script to Alter Crypto Wallets

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows 11 Enhances Taskbar and AI Features
  • Top Cloud Firewall Solutions for 2026: A Comprehensive Guide
  • Balance Theory Secures $19M for Cybersecurity Investment Platform
  • Critical Ruby on Rails Vulnerability Patched
  • Hackers Exploit Adform Script to Alter Crypto Wallets

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark