Tech »  Topic »  Fortinet Patches Critical FortiSandbox Vulnerabilities

Fortinet Patches Critical FortiSandbox Vulnerabilities


Fortinet on Tuesday released 26 advisories detailing 27 vulnerabilities across its products, including two critical-severity flaws in FortiSandbox.

Tracked as CVE-2026-39813, the first of the critical bugs impacts the FortiSandbox JRPC API and could allow attackers to bypass authentication.

The second one, tracked as CVE-2026-39808, is an OS command injection issue that can be exploited for arbitrary code or command execution.

Both security defects have a CVSS score of 9.1 and could be exploited without authentication via specially crafted HTTP requests.

On Tuesday, Fortinet also patched CVE-2026-22828, a high-severity buffer overflow vulnerability in FortiAnalyzer Cloud that could be exploited without authentication for remote code execution or arbitrary command execution.

“Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation. Thanks to network segmentation, this vulnerability could only be exploited if the attacker has already access to another cloud component belonging to the ...


Copyright of this story solely belongs to securityweek . To see the full text click HERE