Three FortiSandbox Bugs Under Active Exploitation, Including a 9.1 Path Traversal
Threat intel firm Defused Cyber flags in-the-wild abuse of CVE-2026-39813, CVE-2026-39808 and CVE-2026-25089 within a 24-hour window.

Key points
- Defused Cyber observed exploitation of three FortiSandbox vulnerabilities over a single 24-hour window.
- CVE-2026-39813, rated 9.1, is a path traversal flaw in the FortiSandbox JRPC API that can expose files outside the intended directory scope.
- CVE-2026-39808 and CVE-2026-25089 are being exploited alongside it.
- No victim attribution or actor identification has been published.
- Defenders should consult vendor advisories at fortiguard.fortinet.com/psirt and apply the relevant builds.
What are these vulnerabilities?
Attackers are hitting Fortinet's FortiSandbox appliance on multiple fronts. Threat intelligence firm Defused Cyber said it has logged exploitation of three distinct flaws in the malware analysis platform over a 24-hour window. The bugs span path traversal and related API weaknesses, and at least one carries a critical score.
CVE-2026-39813 is the headline flaw, rated 9.1. It's a path traversal in the FortiSandbox JRPC API that lets an attacker reach files outside the intended directory scope. In practice that means read access to configuration data or credential material that opens the door to deeper compromise. We covered this CVE when it first appeared on 10 June in our roundup of FortiSandbox, Ivanti and SAP fixes, where it headlined a busy week of vendor advisories. The two companion CVEs being exploited alongside it are CVE-2026-39808 and CVE-2026-25089. Defused Cyber disclosed the activity in a post on X.
Why does the appliance's role matter?
FortiSandbox is the box enterprises drop suspicious files into for detonation and analysis. It sits inline with email and web traffic on a lot of networks. That position, close to the perimeter and trusted by downstream tooling, is exactly what makes it attractive to attackers looking for a quiet foothold. A sandboxing box that has itself been compromised is a particularly awkward problem to detect.
Fortinet appliances have been a recurring entry point for ransomware affiliates and state-aligned operators over the past two years. Initial access brokers have repeatedly listed Fortinet device access on Russian-language forums, and several leak-site victims in 2024 and 2025 were traced back to unpatched FortiOS and FortiManager bugs. A FortiSandbox compromise fits the same playbook.
Should defenders act before a patch is confirmed?
Yes. Waiting on a patch isn't an option when exploitation is already active. Check JRPC API logs for anomalous path parameters and unexpected file reads. Restrict management-plane access to the sandbox to a jump host, not the broader corporate network. Rotate any credentials or API tokens the appliance holds, on the assumption that a successful traversal exposed them. Review outbound connections from the sandbox itself: a detonation box contacting infrastructure it didn't analyse is a strong signal.
Fortinet's PSIRT page is the authoritative source for fix availability and affected versions. Defenders should consult the vendor advisories at fortiguard.fortinet.com/psirt for all three CVEs.
No victim attribution has been published. Defused Cyber described the exploitation as ongoing and has not named the actor or actors involved. The pattern here is familiar: a trusted perimeter appliance, a critical-severity path traversal, active exploitation confirmed before most organisations have acted. That's the window attackers are counting on.



