Fortinet FortiSandbox: Critical Flaws Now Exploited

Three critical vulnerabilities in Fortinet’s FortiSandbox product are being actively exploited by attackers. The US Cybersecurity and Infrastructure Security Agency (CISA) added the flaws to its Known Exploited Vulnerabilities (KEV) catalogue on 16 July 2026, a list that tracks security weaknesses where there is confirmed evidence of real-world attack activity, not just theoretical risk.

Patches have been available from Fortinet since spring 2026. Despite this, a significant number of FortiSandbox installations remain on older, vulnerable versions, which is why attackers are still finding success, and why CISA has stepped in to mandate urgent action.

What is FortiSandbox?

FortiSandbox is an advanced threat analysis appliance made by Fortinet. Unlike a firewall, which blocks known threats at the network boundary, FortiSandbox examines suspicious files and network traffic in a controlled, isolated environment, running potentially dangerous content in a virtual “sandbox” to observe how it behaves before it can reach your users or internal systems. It is typically deployed by organisations that want a deeper layer of inspection on top of their core Fortinet firewall estate.

FortiSandbox is a distinct product from Fortinet’s firewall range (FortiGate). Not all Fortinet customers have it, it tends to appear in environments with more advanced or complex security requirements. If you are unsure whether your organisation uses it, your IT team or managed service provider will be able to tell you.

What are the vulnerabilities?

Three flaws have been identified, all rated critical severity by CISA:

  • CVE-2026-25089 – An OS command injection flaw that allows an unauthenticated attacker to execute arbitrary commands on the device via a specially crafted HTTP request.
  • CVE-2026-39808 – A second OS command injection flaw in the same product, also exploitable without valid credentials or any action from a user inside your organisation.
  • CVE-2026-39813 – A related vulnerability in FortiSandbox with a similar attack profile.

The critical concern across all three is that they require no login credentials and no interaction from anyone on your team. An attacker who can reach the FortiSandbox management interface over the network can potentially take complete control of the device. In a security appliance designed to sit at the heart of your threat detection infrastructure, that is a particularly serious exposure.

Fortinet has released fixes addressing these vulnerabilities. FortiSandbox versions 4.4.9 and 5.0.6 include the necessary patches. Any installation running an older version remains at risk.

Why is this still a problem if patches exist?

This is a pattern that repeats regularly across the cyber security industry. A vendor releases a patch; many organisations apply it promptly; but a significant number do not, whether because of change management processes, resource constraints, or simply because no one saw the advisory. Attackers monitor public vulnerability databases and actively scan the internet for unpatched versions of known-vulnerable products. The window between “patch released” and “actively targeted” is now often measured in days rather than weeks.

CISA’s inclusion of these CVEs in its KEV catalogue is a signal to the wider industry that exploitation is confirmed and ongoing. US federal agencies were required to patch before 19 July 2026. Private-sector organisations are not bound by that mandate, but the underlying risk is the same.

What should you do?

If your organisation runs FortiSandbox:

  • Check your installed version immediately. You should be running version 4.4.9 or later on the 4.x branch, or 5.0.6 or later on the 5.x branch.
  • If you are on an older version, update now. This should be treated as an emergency patch, not a routine scheduled maintenance item.
  • Review management interface exposure. Confirm that the FortiSandbox management interface is not accessible directly from the internet, it should only be reachable from trusted internal or management networks.
  • Check Fortinet’s official security advisories at fortiguard.com/psirt for full technical detail and any further guidance specific to your deployment.

If we manage your Fortinet environment as part of our managed IT services, we have already reviewed your FortiSandbox version and applied or scheduled the relevant updates. If you are in any doubt about your status, contact us and we will confirm exactly where your environment stands.

The wider lesson

Vulnerabilities in security appliances, firewalls, sandboxing tools, VPN gateways, are especially damaging when exploited. These are the devices organisations rely on to keep threats out. When one is compromised, an attacker does not just gain access to one machine; they can establish a foothold inside the very perimeter that was supposed to stop them.

Keeping network security appliances patched and properly configured is a core part of sound cyber security practice, and it is something we take seriously as part of our Fortinet management work. If you would like a broader review of your network security posture, including appliance versions, management interface exposure, and configuration hardening, our team is ready to help.

You can find out more about how we approach security for UK businesses on our IT security page, or explore our Cyber Essentials support if you are thinking about certification. To speak to us directly, get in touch here.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name