Security
Loading…

CVE-2026-39808

CRITICALCVSS 9.8Known Exploited
Description

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

Timeline
Published:April 14th, 2026 4:16 PM
Last modified:July 17th, 2026 5:16 AM
Added to KEV:July 16th, 2026
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

fortinet

Products

fortisandbox
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute