Skip to main content
Change Risk Intel

CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

CVSS
9.8 (Critical)
KEV status
CISA KEV — Listed
First seen (CISA KEV)
Recommended change window
Emergency change — patch alongside CVE-2026-25089; single Fortinet maintenance window covers both.
Affected products
Fortinet FortiSandbox

Why this one matters to a CAB

This is the second FortiSandbox command-injection CVE added to KEV on the same day as CVE-2026-25089 and it lives in an adjacent code path in the same HTTP management stack. Treat them as one incident, not two — the change record should reference both.

Defender’s angle

  • Do one firmware update, not two: the Fortinet advisory FG-IR-26-100 lists overlapping fixed builds with FG-IR-26-141. Bundling avoids two rollback drills in one week.
  • Post-patch verification: after upgrade, diagnose test application httpsd 44 on the FortiSandbox will print the running build; capture that string in the change record as proof of remediation.
  • Log retention: extend the FortiSandbox syslog forwarding to keep the pre-patch management-plane logs for 90 days. Investigators will need them if an incident is discovered later.

What to bring to CAB

One combined change record for CVE-2026-25089 and CVE-2026-39808, one maintenance window, one rollback snapshot. Splitting doubles the operational risk without halving the attack window.

Sources

This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.