
FortiSandbox
FortiSandbox is a Fortinet malware-analysis and threat-detection appliance.
Last refreshed: 24 July 2026 · Appears in 1 active topic
CrowdSec caught this FortiSandbox flaw a month before CISA did, so how far behind is the federal patch clock?
Timeline for FortiSandbox
CISA's KEV list runs a month late
Cybersecurity: Threats and DefencesBackground
Fortinet's FortiSandbox malware-analysis appliance was under active exploitation of CVE-2026-39808 from 17 June 2026, the same day CrowdSec shipped a detection rule, but CISA did not ADD the flaw to its Known Exploited Vulnerabilities catalogue until 16 July, a one-month gap.
FortiSandbox is a Fortinet appliance used for malware analysis and threat detection. The KEV entry starts the Binding Operational Directive 26-04 patching clock for federal agencies; CISA's own record still lists the flaw's ransomware association as Unknown.
The appliance extends a wider run of Fortinet exposure the beat has followed, with earlier Fortinet credential-theft flaws later tied to established ransomware crews, underscoring how long a detected flaw can sit before it starts a mandatory federal Deadline.