The U.S. Cybersecurity and Infrastructure Safety Company (CISA) on Thursday ordered authorities companies to prioritize patching two vulnerabilities at present being exploited within the Fortinet FortiSandbox risk detection platform.
These two severity safety flaws (tracked as CVE-2026-39808 and CVE-2026-25089) have been addressed by Fortinet on April 14th and June ninth, respectively.
As detailed in a safety advisory issued by the corporate on the time, a profitable exploit may permit an unauthenticated attacker to remotely execute malicious code through a low-complexity command injection assault that doesn’t require consumer interplay.
To resolve these points and block incoming assaults, directors should improve all affected deployments to the most recent launched model.
Though Fortinet has not but tagged these two vulnerabilities as being utilized in an assault or responded to BleepingComputer’s electronic mail relating to precise exploitation, risk intelligence agency Defused revealed on June 16 that attackers have begun exploiting these two vulnerabilities within the wild.
“Over the previous 24 hours, we have now noticed exploitation of a number of Fortinet FortiSandbox vulnerabilities, together with CVE-2026-39813 (no identified exploits to this point), CVE-2026-39808, and CVE-2026-25089 (vibe-coded and presumably flawed exploit),” Defused warned.
CISA additionally confirmed Thursday that these flaws are being actively exploited within the wild and added them to its catalog of identified exploited vulnerabilities. As mandated by Binding Working Directive (BOD) 26-04, U.S. federal companies should patch susceptible FortiSandbox situations by Sunday, July nineteenth.
In February, Fortinet additionally patched a crucial SQL injection vulnerability (CVE-2026-21643) within the FortiClient Enterprise Administration Server (EMS) platform, however Defused reported a month later that the vulnerability was being actively exploited.
Two months later, the corporate addressed one other safety problem exploited within the assault: a path traversal vulnerability (CVE-2025-61624) that might permit an authenticated attacker to escalate privileges.
Fortinet vulnerabilities are sometimes exploited in cyber espionage and ransomware assaults (usually zero-day). CISA has tracked a complete of 28 Fortinet vulnerabilities which were exploited in assaults in recent times, 13 of which have additionally been utilized in ransomware assaults.

Safety groups doc 54% of profitable assaults and problem a warning on solely 14%. The remainder strikes invisibly by way of the surroundings.
Picus’ whitepaper reveals methods to check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
