
FortiSandbox
Fortinet malware-sandbox appliance whose command-injection flaw CVE-2026-39808 sat uncatalogued by CISA for a month.
FortiSandbox is Fortinet's malware-analysis appliance, actively exploited via CVE-2026-39808 from 17 June 2026 but not added to CISA's KEV catalogue until 16 July, a month later.
Last refreshed: 3 August 2026 · Appears in 1 active topic
CrowdSec caught this FortiSandbox flaw a month before CISA did, so how far behind is the federal patch clock?
Timeline for FortiSandbox
Mentioned in: Arista, Fortinet and Cisco flaws listed
Cybersecurity: Threats and DefencesCISA's KEV list runs a month late
Cybersecurity: Threats and DefencesBackground
FortiSandbox is Fortinet's malware-analysis and threat-detection appliance, used by organisations to detonate and inspect suspicious files in an isolated environment before they reach production systems.
As a security appliance itself, a flaw in FortiSandbox carries particular weight: the tool exists to catch threats, so a vulnerability in it can undermine the very detection layer it is meant to provide.
FortiSandbox forms part of Fortinet's wider Security Fabric product family, typically deployed alongside firewalls and endpoint tools rather than standalone, so an unpatched flaw in the appliance can have knock-on effects for the broader security stack it feeds detection signals into.
FortiSandbox's flaw reached KEV a month late
CrowdSec spotted active exploitation of a flaw in FortiSandbox on 17 June 2026. CISA did not ADD that flaw, CVE-2026-39808, to its KEV catalogue until 16 July, a full month after in-the-wild exploitation was first observed.
The delay matters because organisations that treat KEV listing as their trigger for urgent patching had no official signal to act on FortiSandbox for four weeks after attackers were already using the flaw. FortiSandbox was later grouped with Arista and Cisco entries in a further batch CISA added between 24 July and 3 August.