Skip to content
You can now search across every topic, entity and event.What's new
FortiSandbox
Product

FortiSandbox

Fortinet malware-sandbox appliance whose command-injection flaw CVE-2026-39808 sat uncatalogued by CISA for a month.

FortiSandbox is Fortinet's malware-analysis appliance, actively exploited via CVE-2026-39808 from 17 June 2026 but not added to CISA's KEV catalogue until 16 July, a month later.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

CrowdSec caught this FortiSandbox flaw a month before CISA did, so how far behind is the federal patch clock?

Timeline for FortiSandbox

#12 28 Jul
#11 16 Jul

CISA's KEV list runs a month late

Cybersecurity: Threats and Defences
View full timeline →

Background

FortiSandbox is Fortinet's malware-analysis and threat-detection appliance, used by organisations to detonate and inspect suspicious files in an isolated environment before they reach production systems.

As a security appliance itself, a flaw in FortiSandbox carries particular weight: the tool exists to catch threats, so a vulnerability in it can undermine the very detection layer it is meant to provide.

FortiSandbox forms part of Fortinet's wider Security Fabric product family, typically deployed alongside firewalls and endpoint tools rather than standalone, so an unpatched flaw in the appliance can have knock-on effects for the broader security stack it feeds detection signals into.

Key Issues
KEV listing lag

FortiSandbox's flaw reached KEV a month late

CrowdSec spotted active exploitation of a flaw in FortiSandbox on 17 June 2026. CISA did not ADD that flaw, CVE-2026-39808, to its KEV catalogue until 16 July, a full month after in-the-wild exploitation was first observed.

The delay matters because organisations that treat KEV listing as their trigger for urgent patching had no official signal to act on FortiSandbox for four weeks after attackers were already using the flaw. FortiSandbox was later grouped with Arista and Cisco entries in a further batch CISA added between 24 July and 3 August.

Common Questions
What is FortiSandbox?
FortiSandbox is a Fortinet appliance used for malware analysis and threat detection, deployed by organisations to catch attacks other defences miss.Source: CrowdSec
Why did CISA take a month to catalogue the FortiSandbox flaw?
CrowdSec detected in-the-wild exploitation of CVE-2026-39808 on 17 June 2026, but CISA did not ADD it to its Known Exploited Vulnerabilities catalogue until 16 July, the gap that starts the federal patching Deadline.Source: CrowdSec
Has any ransomware group been linked to the FortiSandbox CVE-2026-39808 flaw?
No. As of early August 2026, CISA's Known Exploited Vulnerabilities catalogue still lists the ransomware association for CVE-2026-39808 as Unknown, so no crew exploiting it has been publicly named.Source: CISA KEV catalogue
What kind of vulnerability is CVE-2026-39808 in FortiSandbox?
CVE-2026-39808 is an operating-system command-injection flaw in Fortinet's FortiSandbox appliance, the class of defect that lets an attacker run arbitrary system commands through the product's own interface.Source: CrowdSec