• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-39808: pre-auth remote code execution in Fortinet FortiSandbox

An attacker able to reach a Fortinet FortiSandbox instance over the network can submit crafted requests that result in execution of operating-system commands without needing any credentials, potentially giving full control of the appliance; this is tracked as CVE-2026-39808. The issue affects FortiSandbox 4.4.0–4.4.8 and multiple FortiSandbox PaaS builds (vendor-listed examples include 23.4.4374, 23.4.4350, 23.3.4329, 23.1.4245 and several 22.x and 21.x builds). Exploitation only requires network access to the vulnerable FortiSandbox service.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.47362
CWE
CWE-78
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA added CVE-2026-39808 to the Known Exploited Vulnerabilities catalog with a July 19, 2026 remediation deadline and proof-of-concept code is public — immediately reduce internet exposure and apply vendor mitigations.

What is CVE-2026-39808?

An attacker able to reach a Fortinet FortiSandbox instance over the network can submit crafted requests that result in execution of operating-system commands without needing any credentials, potentially giving full control of the appliance; this is tracked as CVE-2026-39808. The issue affects FortiSandbox 4.4.0–4.4.8 and multiple FortiSandbox PaaS builds (vendor-listed examples include 23.4.4374, 23.4.4350, 23.3.4329, 23.1.4245 and several 22.x and 21.x builds). Exploitation only requires network access to the vulnerable FortiSandbox service. The weakness is classified as CWE-78 (OS Command Injection).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Fortinet FortiSandbox are affected?

BRANCHAFFECTEDFIXED
FortiSandbox 4.x4.4.0 – 4.4.8
FortiSandbox PaaS 23.x23.4.4374
FortiSandbox PaaS 23.x23.4.4350
FortiSandbox PaaS 23.x23.3.4329
FortiSandbox PaaS 23.x23.1.4245
FortiSandbox PaaS 22.x22.2.4151
FortiSandbox PaaS 22.x22.2.4134
FortiSandbox PaaS 22.x22.1.4113
FortiSandbox PaaS 21.x21.4.4072
FortiSandbox PaaS 21.x21.3.4055

Is CVE-2026-39808 being exploited?

CISA added CVE-2026-39808 to the Known Exploited Vulnerabilities catalog on 2026-07-16, and US federal agencies must remediate by 2026-07-19; public exploit code is also available.

How to fix CVE-2026-39808

  1. Remove or block internet access to FortiSandbox instances until mitigations or a vendor patch are available.
  2. Implement Fortinet's recommended mitigations immediately (follow vendor guidance).
  3. Restrict FortiSandbox network access to trusted management subnets and firewall only necessary ports.
  4. Increase logging and monitor for suspicious inbound requests and unexpected command execution activity.

Frequently asked questions

Is CVE-2026-39808 being actively exploited?

CISA added CVE-2026-39808 to its Known Exploited Vulnerabilities catalog on 2026-07-16 and public exploit code is available.

Which FortiSandbox versions are affected by CVE-2026-39808?

FortiSandbox 4.4.0 through 4.4.8 and several FortiSandbox PaaS builds (including 23.4.4374, 23.4.4350, 23.3.4329, 23.1.4245 and multiple 22.x and 21.x builds) are listed as affected.

Is there a patch for CVE-2026-39808?

No fixed versions are listed in the vendor data; apply vendor mitigations and restrict access until Fortinet releases patches.

Does CVE-2026-39808 require authentication?

No; the vulnerability can be triggered by crafted network requests without valid credentials against FortiSandbox.

References