← Blog
🛡️ Vulnerability5 August 2026

CVE-2026-39808: Critical Command Injection Vulnerability in Fortinet FortiSandbox

CVE-2026-39808, a critical vulnerability (CVSS 9.8) in FortiSandbox, listed in CISA's KEV catalog. What to do if you use this product.

OCIRIA security team

CVE-2026-39808: Critical Command Injection Vulnerability in Fortinet FortiSandbox

In short

CVE-2026-39808 has been identified, a critical OS command injection vulnerability in Fortinet FortiSandbox [1]. It has a CVSS score of 9.8 out of 10, rated critical [1], and appears in CISA's Known Exploited Vulnerabilities (KEV) catalog [2]. If your organization uses FortiSandbox in versions 4.4.0 through 4.4.8 [1], the recommendation is to treat this as a priority this very week: check the installed version, apply the vendor's update, and review access.

What it is and why it matters

FortiSandbox is a Fortinet platform used by many companies to analyze files and detect malware before it reaches the corporate network. CVE-2026-39808 is an OS command injection vulnerability: a flaw in how the software handles certain input, which under certain conditions could allow unauthorized commands to be executed on the affected system [1]. According to the official record, it affects versions 4.4.0 through 4.4.8 of FortiSandbox [1].

The CVSS score of 9.8 places it in the highest severity range [1]. We do not have additional published information about the exact attack vector (for example, whether it requires prior privileges or user interaction), so we avoid making assumptions about it; what matters is that the vendor and NVD classify it as critical [1].

One element that reinforces the urgency: this CVE is included in CISA's KEV catalog [2], which indicates that cybersecurity agencies consider it a known exploited vulnerability and recommend remediating it as a priority. Our OCIRIA radar has classified it under the "Command Injection" category with critical severity, in line with this assessment.

Who is affected

This affects organizations that have deployed Fortinet FortiSandbox in the versions noted (4.4.0 to 4.4.8) [1]. It is especially relevant for companies that use FortiSandbox as part of their perimeter security or threat analysis infrastructure, since it is often connected to other critical systems on the network. Based on available sources, we have no evidence that it affects products or versions other than those indicated.

How to know if you are vulnerable

  • Check the exact version of FortiSandbox installed in your organization and compare it against the affected range (4.4.0 to 4.4.8) [1].
  • Review the inventory of assets exposed to the internet or accessible from less trusted networks: any malware analysis system with an accessible administration interface is a point worth auditing.
  • Check your exposed attack surface: identifying which services and versions are visible from outside is the first step before deciding patching priorities.
  • Review access logs and unusual activity in the recent period, given that this vulnerability is listed as actively exploited according to CISA [2].

How to protect yourself

1. Identify whether you have FortiSandbox version 4.4.0 to 4.4.8 in your inventory [1].

2. Update to the fixed version indicated by Fortinet as soon as it is available for your environment; consult the vendor's official bulletin to find out the target version.

3. Restrict access to the FortiSandbox administration interface to trusted networks only while the patch is applied.

4. Audit historical access: review logs to rule out anomalous activity, especially given that the CVE is listed in CISA's KEV catalog [2].

5. Prioritize this fix over others of lower severity: a CVSS score of 9.8 and presence in KEV are clear signs of urgency [1][2].

Frequently asked questions

Is it a critical vulnerability?

Yes, NVD classifies it with critical severity and CVSS 9.8 [1].

Is it being exploited?

It appears in CISA's KEV catalog, which lists vulnerabilities with known exploitation [2]. We do not have additional details about specific campaigns.

Does it require authentication to be exploited?

This is not data published by the vendor or by NVD in the available sources, so we cannot state this either way.

Which versions are affected?

FortiSandbox 4.4.0 to 4.4.8, according to the official record [1].

What should I do today?

Check the installed version, restrict access to the administration interface, and plan the update as a high priority.

Sources

  • [1] https://nvd.nist.gov/vuln/detail/CVE-2026-39808
  • [2] https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json
OCIRIA security team Threat monitoring & response · data from our real-time radar Live radar