Skip to content
You can now search across every topic, entity and event.What's new
FortiSandbox
Product

FortiSandbox

FortiSandbox is a Fortinet malware-analysis and threat-detection appliance.

Last refreshed: 24 July 2026 · Appears in 1 active topic

Key Question

CrowdSec caught this FortiSandbox flaw a month before CISA did, so how far behind is the federal patch clock?

Timeline for FortiSandbox

#11 16 Jul

CISA's KEV list runs a month late

Cybersecurity: Threats and Defences
View full timeline →

Background

Fortinet's FortiSandbox malware-analysis appliance was under active exploitation of CVE-2026-39808 from 17 June 2026, the same day CrowdSec shipped a detection rule, but CISA did not ADD the flaw to its Known Exploited Vulnerabilities catalogue until 16 July, a one-month gap.

FortiSandbox is a Fortinet appliance used for malware analysis and threat detection. The KEV entry starts the Binding Operational Directive 26-04 patching clock for federal agencies; CISA's own record still lists the flaw's ransomware association as Unknown.

The appliance extends a wider run of Fortinet exposure the beat has followed, with earlier Fortinet credential-theft flaws later tied to established ransomware crews, underscoring how long a detected flaw can sit before it starts a mandatory federal Deadline.

Common Questions
What is FortiSandbox?
FortiSandbox is a Fortinet appliance used for malware analysis and threat detection, deployed by organisations to catch attacks other defences miss.Source: CrowdSec
Why did CISA take a month to catalogue the FortiSandbox flaw?
CrowdSec detected in-the-wild exploitation of CVE-2026-39808 on 17 June 2026, but CISA did not ADD it to its Known Exploited Vulnerabilities catalogue until 16 July, the gap that starts the federal patching Deadline.Source: CrowdSec