Fortinet FortiSandbox Vulnerabilities Actively Exploited in Widespread Enterprise Attacks

Defused said the CVE-2026-25089 exploit appeared to be “created using AI,” and it “did not work when first observed” by the company—suggesting attackers may still be refining weaponization.
CVE-2026-39813 is not just an authentication-bypass issue: The Register reports it as a path traversal flaw in the FortiSandbox JRPC API that enables authentication bypass via specially crafted HTTP requests, affecting FortiSandbox 4.4.0–4.4.8 and 5.0.0–5.0.5, with fixes in FortiSandbox 4.4.9+ and 5.0.6+ (depending on branch).
The FortiBleed campaign’s scope and geography were described by SOCRadar as well: it involved more than 30,000 compromised Fortinet firewalls, with many of the exposed devices located in India and the United States.
Fortra’s BoKS flaw (CVE-2026-9862) includes operational specifics: Fortra disclosed it on June 15, 2026, after it was discovered on May 27, 2026, and it affects the boks_autoregisterd service that listens by default on port 6507 (CWE-78).
The Register also reports that Fortinet assigned 9.1 CVSS ratings to the three FortiSandbox CVEs and, at the time of patching, the vendor said there were no reports of active exploitation—contrasting with the later claims of in-the-wild abuse.
Three critical vulnerabilities in Fortinet's FortiSandbox security appliance are under active attack, with exploit attempts observed within days of patches going public, according to SecurityWeek and The Register. The flaws carry 9.1 CVSS severity ratings and allow attackers to bypass authentication and run arbitrary commands — all without a single click from a victim.
At the same time, a separate campaign called FortiBleed has compromised more than 30,000 Fortinet firewalls and VPN gateways across 194 countries, turning them into listening posts to harvest credentials, SOCRadar found. Together, the two threats mark one of the most aggressive stretches of Fortinet-focused attacks in recent memory.
Fortinet patched CVE-2026-39808 and CVE-2026-39813 on April 14, telling customers there was no sign of active exploitation at the time. That changed fast. By June 12, threat intelligence firm KEVIntel had spotted the first live attacks against CVE-2026-39808, according to SecurityWeek. Three days later, both KEVIntel and Defused reported exploitation of CVE-2026-39813 as well.
A third flaw, CVE-2026-25089, was patched on June 9 and targeted by June 16. Defused said the exploit appeared to be "created using an AI model" and was initially "faulty" — suggesting attackers are refining it in real time. The Register reports that CVE-2026-39813 is a path traversal bug in the FortiSandbox JRPC API, affecting versions 4.4.0–4.4.8 and 5.0.0–5.0.5, with fixes in 4.4.9+ and 5.0.6+.
A sandbox is the appliance that detonates suspicious files to decide if they are safe. Compromising it lets attackers do three dangerous things: whitelist their own malware, watch every suspicious file crossing the network, and use the appliance as a jumping-off point for deeper intrusion. That makes FortiSandbox a uniquely high-value target, as noted by analysts at LinkedIn.
Fortinet's own vendor statement — "known exploited: no" — was still live on PSIRT advisories when researchers were already sharing forensic evidence of in-the-wild abuse. The Register highlighted this gap, calling it a trust problem for administrators who may have deprioritized the April patches based on the vendor's initial word.
Separate from the FortiSandbox exploits, SOCRadar uncovered a systematic campaign it calls FortiBleed. Attackers scan the internet for Fortinet devices and try a curated list of known passwords against each one. Once inside, they use the device as a "listening post" to collect credentials for other internal systems. SOCRadar confirmed 30,791 compromised devices, with the United States and India showing the highest concentration of exposed hardware.
The tactic is called "living off the land" — using real credentials instead of complex exploits, making detection much harder for security teams. A credential reset on all Fortinet administrative accounts is now considered mandatory for any organization with internet-facing Fortinet devices. Patching alone will not be enough if passwords have already been stolen.
Adding to the pressure on security teams, Fortra disclosed a command injection flaw in its Core Privileged Access Manager, known as BoKS, on June 15. The bug, CVE-2026-9862, was discovered May 27. It sits in the boks_autoregisterd service, which listens on port 6507 by default. A remote attacker with no credentials and no user interaction can use it to run elevated commands, according to GBHackers.
Critically, Fortra disclosed the flaw without providing a patch. Security researchers at GBHackers warn this may be more dangerous than the Fortinet issues because it targets privileged access management — the tool that controls who gets the keys to every other system. Until a fix arrives, organizations should block port 6507 at the network perimeter immediately.
Publishers
16
Articles
4
Reach
20