DIRAS TAKE
Urgent: CISA added CVE-2026-39808 to the Known Exploited Vulnerabilities catalog with a July 19, 2026 remediation deadline and proof-of-concept code is public — immediately reduce internet exposure and apply vendor mitigations.
What is CVE-2026-39808?
An attacker able to reach a Fortinet FortiSandbox instance over the network can submit crafted requests that result in execution of operating-system commands without needing any credentials, potentially giving full control of the appliance; this is tracked as CVE-2026-39808. The issue affects FortiSandbox 4.4.0–4.4.8 and multiple FortiSandbox PaaS builds (vendor-listed examples include 23.4.4374, 23.4.4350, 23.3.4329, 23.1.4245 and several 22.x and 21.x builds). Exploitation only requires network access to the vulnerable FortiSandbox service. The weakness is classified as CWE-78 (OS Command Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Fortinet FortiSandbox are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| FortiSandbox 4.x | 4.4.0 – 4.4.8 | |
| FortiSandbox PaaS 23.x | 23.4.4374 | |
| FortiSandbox PaaS 23.x | 23.4.4350 | |
| FortiSandbox PaaS 23.x | 23.3.4329 | |
| FortiSandbox PaaS 23.x | 23.1.4245 | |
| FortiSandbox PaaS 22.x | 22.2.4151 | |
| FortiSandbox PaaS 22.x | 22.2.4134 | |
| FortiSandbox PaaS 22.x | 22.1.4113 | |
| FortiSandbox PaaS 21.x | 21.4.4072 | |
| FortiSandbox PaaS 21.x | 21.3.4055 |
Is CVE-2026-39808 being exploited?
CISA added CVE-2026-39808 to the Known Exploited Vulnerabilities catalog on 2026-07-16, and US federal agencies must remediate by 2026-07-19; public exploit code is also available.
How to fix CVE-2026-39808
- Remove or block internet access to FortiSandbox instances until mitigations or a vendor patch are available.
- Implement Fortinet's recommended mitigations immediately (follow vendor guidance).
- Restrict FortiSandbox network access to trusted management subnets and firewall only necessary ports.
- Increase logging and monitor for suspicious inbound requests and unexpected command execution activity.
Frequently asked questions
Is CVE-2026-39808 being actively exploited?
CISA added CVE-2026-39808 to its Known Exploited Vulnerabilities catalog on 2026-07-16 and public exploit code is available.
Which FortiSandbox versions are affected by CVE-2026-39808?
FortiSandbox 4.4.0 through 4.4.8 and several FortiSandbox PaaS builds (including 23.4.4374, 23.4.4350, 23.3.4329, 23.1.4245 and multiple 22.x and 21.x builds) are listed as affected.
Is there a patch for CVE-2026-39808?
No fixed versions are listed in the vendor data; apply vendor mitigations and restrict access until Fortinet releases patches.
Does CVE-2026-39808 require authentication?
No; the vulnerability can be triggered by crafted network requests without valid credentials against FortiSandbox.
References
- nvd.nist.gov/vuln/detail/CVE-2026-39808
- cve.org/CVERecord?id=CVE-2026-39808
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-39808
- fortiguard.fortinet.com/psirt/FG-IR-26-100
- All Fortinet CVEs on CVE Radar
- CVEs published in September 2026