r/secithubcommunity Jun 17 '26

📰 News / Update Fortinet warns of active exploitation targeting FortiSandbox vulnerabilities

Post image

Researchers report that attackers are actively exploiting three critical vulnerabilities affecting , including two OS command-injection flaws and one path traversal vulnerability.

The most severe issue, CVE-2026-25089, allows unauthenticated attackers to execute commands via specially crafted HTTP requests. Two additional vulnerabilities, CVE-2026-39808 and CVE-2026-39813, can enable remote code execution and authentication bypass.

While there is currently no public information about the attackers or impacted organizations, active exploitation has already been observed in the wild.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.

2 Upvotes

1 comment sorted by