Affected Systems
Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.
Exploitation Status
Active exploitation confirmed by Defused Cyber within past 24 hours. Threat actors are targeting these vulnerabilities in the wild.
Business Impact
Organizations running FortiSandbox face immediate compromise risk. FortiSandbox is typically deployed as a security control for malware analysis, making it a high-value target. Successful exploitation could allow attackers to bypass sandboxing, gain unauthorized access, or pivot to internal networks. Specific attack vectors and exploit details not yet public. CVSS scores for CVE-2026-39808 and CVE-2026-25089 not disclosed.
Urgency
🔴 Immediate
Recommended Actions
- Immediately identify all FortiSandbox instances in your environment and isolate or restrict network access until patched
- Apply latest Fortinet security updates for FortiSandbox; check Fortinet PSIRT advisories for CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089
- Review FortiSandbox logs for indicators of compromise: unusual authentication attempts, configuration changes, or unexpected outbound connections
- If patching cannot be completed within 24 hours, consider temporarily disabling FortiSandbox or placing behind additional access controls
- Monitor Fortinet security advisories and threat intelligence feeds for IOCs, exploit details, and additional mitigation guidance
---
# Threat Actor Context
Actor Profile
The threat actor behind this exploitation campaign remains unattributed. Motivation appears to be opportunistic exploitation of recently disclosed Fortinet FortiSandbox vulnerabilities for initial access. The actor demonstrates capability to rapidly weaponize public vulnerabilities, with exploitation observed within 24 hours of disclosure according to Defused Cyber. The origin, sophistication level, and ultimate objectives (ransomware deployment, espionage, botnet recruitment) are currently unknown pending further investigation.
TTPs (Tactics, Techniques, Procedures)
Initial Access (T1190 - Exploit Public-Facing Application): Active exploitation of CVE-2026-39813 (CVSS 9.1 critical severity), CVE-2026-39808, and CVE-2026-25089 targeting Fortinet FortiSandbox appliances. The high CVSS score of CVE-2026-39813 suggests potential for unauthenticated remote code execution or significant security bypass. Exploitation occurred within 24 hours of public disclosure, indicating rapid weaponization capabilities. The targeting of security infrastructure (sandbox appliances) may enable adversaries to bypass malware detection, manipulate threat analysis, or pivot to connected networks.
Targets & Patterns
Primary targets are organizations utilizing Fortinet FortiSandbox appliances, with confirmed targeting of the security sector. FortiSandbox is deployed by enterprises, MSSPs, and security operations centers for malware analysis and threat detection, making these high-value targets. Compromising sandbox infrastructure allows adversaries to evade detection, manipulate analysis results, or gain privileged network access. The security sector focus suggests either opportunistic scanning for vulnerable appliances or deliberate targeting to undermine defensive capabilities. Organizations in any vertical deploying FortiSandbox for perimeter defense are at risk.
Historical Context
This campaign follows a pattern of rapid exploitation of Fortinet vulnerabilities observed in recent years. Previous incidents include exploitation of FortiOS SSL-VPN flaws (CVE-2023-27997, CVE-2022-42475) by multiple APT groups including Chinese and Iranian-nexus actors. Fortinet appliances remain attractive targets due to their perimeter placement and privileged network position. The 24-hour exploitation window aligns with trends of N-day vulnerability weaponization by both APT groups and cybercrime actors. No direct linkage to previous Fortinet-targeting campaigns has been established at this time.
Defensive Recommendations
- Immediately patch FortiSandbox appliances to the latest firmware version addressing CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089
- Monitor FortiSandbox logs for anomalous authentication attempts, unexpected configuration changes, or suspicious administrative activity (T1190 detection)
- Implement network segmentation to isolate FortiSandbox appliances from critical production networks and restrict management interface access to trusted IP ranges
- Deploy detection rules for exploitation attempts targeting known Fortinet CVEs, including monitoring for unusual HTTP/HTTPS requests to management interfaces
- Conduct forensic review of FortiSandbox appliances for indicators of compromise if patching was delayed beyond the 24-hour exploitation window, including reviewing user accounts, scheduled tasks, and file integrity
