CVE-2026-39808
exploitation · critical · Evidence score 90
- Vendor
- Fortinet
- Affected software
- Fortinet FortiSandbox
- Exploitation signal
- Listed in CISA Known Exploited Vulnerabilities
- EPSS
- 0.9121
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Provenance
CISA Known Exploited Vulnerabilities
16 July 2026, 10:00 AM AEST