Security News

Cybersecurity news aggregator

🛡️
CRITICAL Vulnerabilities Help Net Security

Attackers are exploiting FortiSandbox vulnerabilities

Attackers are actively exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a critical security platform that provides threat verdicts to other Fortinet products. One of the exploits is described as vibecoded and likely faulty. The article notes that Fortinet disclosed CVE-2026-39813 and CVE-2026-39808 in April 2026, with the former being a path traversal vulnerability, but it does not provide specific affected version ranges, fixed versions, CVSS scores, or workarounds.
Read Full Article →

Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from threat intelligence company Defused, which said that the exploit for one of the flaws is vibecoded, and likely faulty. The vulnerabilities Fortinet disclosed CVE-2026-39813 and CVE-2026-39808 in April 2026. The former is a path traversal vulnerability in … More → The post Attackers are exploiting FortiSandbox vulnerabilities appeared first on Help Net Security .

Share this article