CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

June 25, 2026

Threat actors are actively exploiting three security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. The flaws include CVE-2026-39813 (path traversal), CVE-2026-39808 (OS command injection), and CVE-2026-25089 (OS command injection), all with a CVSS score of 9.1. The first two were patched in April 2026, while CVE-2026-25089 was fixed last week. Defused Cyber noted that the exploit for CVE-2026-25089 shows signs of AI development but is faulty, with no working exploit publicly disclosed.

Separately, SOCRadar disclosed a large-scale campaign dubbed ‘FortiBleed’ where suspected Russian-speaking threat actors compromised over 30,000 Fortinet firewalls across 194 countries. The attackers used a two-step approach: first, they attempted previously leaked Fortinet passwords against internet-exposed devices; second, they passively monitored network traffic to collect additional credentials. Hudson Rock later reported that the campaign targeted 73,932 unique firewall URLs, resulting in 21,632 unique affected domains. The attackers intercepted SSL-VPN authentication, cracked hashes on a 45-GPU cluster, and pivoted into Active Directory environments.

Fortinet stated that the credential collection stemmed from previous incidents and brute-force attacks, not a new security flaw. The company urged organizations to follow best practices, including regular credential rotation and multi-factor authentication.

CVEs: CVE-2026-39813, CVE-2026-39808, CVE-2026-25089, CVE-2026-35616, CVE-2026-11645

Attack groups: Russian-speaking threat actors

Companies: Fortinet, Defused Cyber, SOCRadar, Hudson Rock

Products: FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS, FortiGate, FortiClient EMS