Planet Briefing

First published · Last updated

CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability

The source reports an OS command injection vulnerability in Fortinet FortiSandbox that could allow an unauthenticated attacker to execute unauthorized code or commands through crafted HTTP requests. It calls for applying mitigations in line with vendor instructions and applicable CISA guidance.

Photo of the firewall Fortinet FortiGate 6501F.
Illustrative image: Photo of the firewall Fortinet FortiGate 6501F. — Premeditated/Wikimedia Commons, CC BY-SA 4.0

Categories: technology

Generated scores

Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.

Confidence
5/10
Geographic reach
1/10
Global importance
2/10
Impact magnitude
3/10
Positivity
2/10
Urgency
5/10

Why it matters

The source identifies a potential route to unauthorized code execution and calls for mitigation or discontinuing use if mitigations are unavailable.

Sources

Report an issue