Threat actors are actively exploiting three security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. The flaws include CVE-2026-39813 (path traversal), CVE-2026-39808 (OS command injection), and CVE-2026-25089 (OS command injection), all with a CVSS score of 9.1. The first two were patched in April 2026, while CVE-2026-25089 was fixed last week. Defused Cyber noted that the exploit for CVE-2026-25089 shows signs of AI development but is faulty, with no working exploit publicly disclosed.
Separately, SOCRadar disclosed a large-scale campaign dubbed ‘FortiBleed’ where suspected Russian-speaking threat actors compromised over 30,000 Fortinet firewalls across 194 countries. The attackers used a two-step approach: first, they attempted previously leaked Fortinet passwords against internet-exposed devices; second, they passively monitored network traffic to collect additional credentials. Hudson Rock later reported that the campaign targeted 73,932 unique firewall URLs, resulting in 21,632 unique affected domains. The attackers intercepted SSL-VPN authentication, cracked hashes on a 45-GPU cluster, and pivoted into Active Directory environments.
Fortinet stated that the credential collection stemmed from previous incidents and brute-force attacks, not a new security flaw. The company urged organizations to follow best practices, including regular credential rotation and multi-factor authentication.
CVEs: CVE-2026-39813, CVE-2026-39808, CVE-2026-25089, CVE-2026-35616, CVE-2026-11645
Attack groups: Russian-speaking threat actors
Companies: Fortinet, Defused Cyber, SOCRadar, Hudson Rock
Products: FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS, FortiGate, FortiClient EMS
Original source: thehackernews.com