Critical Fortinet FortiSandbox Bugs Actively Exploited

🔴 Critical | Source: The Register — Security Three critical vulnerabilities in Fortinet’s FortiSandbox product have been actively exploited by unknown attackers in the wild. Patches are available for all three flaws, making urgent remediation essential for any organisation running FortiSandbox. The active exploitation status significantly raises the risk, as attackers are already leveraging these weaknesses before many organisations have had a chance to respond. Security Architect’s Take: If FortiSandbox is deployed anywhere in your environment — on-premises or integrated with cloud workloads — prioritise patching immediately and review logs for indicators of compromise prior to the patch window. Isolate affected appliances from the network if an immediate upgrade is not possible. ...

16 June 2026 Â· ZX Cloud Security

Fortinet FortiSandbox CVE-2026-39813 Exploited in Wild

🔴 Critical | Source: The Hacker News Attackers are actively exploiting three vulnerabilities in Fortinet FortiSandbox, a network security sandboxing product, including a critical path traversal flaw (CVE-2026-39813, CVSS 9.1) in its JRPC API. Two additional CVEs — CVE-2026-39808 and CVE-2026-25089 — are also being abused in the wild, with at least one patched only last week. Active exploitation makes this an urgent patching priority for any organisation running FortiSandbox. Security Architect’s Take: Immediately apply the latest Fortinet patches for FortiSandbox and audit internet-facing exposure of the JRPC API — if it does not need to be externally accessible, restrict it at the network perimeter. Check threat intelligence feeds and FortiSandbox logs for indicators of compromise consistent with path traversal attempts. ...

16 June 2026 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. Learn more