CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-39808: FortiSandbox OS Command Injection Vulnerability

June 25, 2026

An OS command injection vulnerability in FortiSandbox that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. CVSS score 9.1. Patched by Fortinet in April 2026.