CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-07-16. EPSS: 47.4% chance of exploitation in the next 30 days.

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Affected products

  • Fortinet FortiSandbox: from 4.4.0, up to and including 4.4.9

Published 2026-04-14. Last modified 2026-07-17.