Rewterz

Windows LegacyHive 0-Day Gains Admin Access

July 17, 2026
How-AI-Improves-Threat-Intelligence-Analysis-and-Security-Decision-Making

How AI Improves Threat Intelligence Analysis and Security Decision Making

July 20, 2026

CISA Warns of Exploited FortiSandbox Flaws

Severity

High

Analysis Summary

CISA has added two critical Fortinet FortiSandbox vulnerabilities, CVE-2026-39808 and CVE-2026-25089, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in real-world attacks. Both flaws are OS command injection vulnerabilities (CWE-78) that allow remote, unauthenticated attackers to execute arbitrary operating system commands by sending specially crafted HTTP requests. Successful exploitation requires no valid credentials, making these vulnerabilities particularly dangerous for internet-facing deployments.

The vulnerabilities impact multiple Fortinet products. CVE-2026-39808 affects FortiSandbox, while CVE-2026-25089 impacts FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. Because FortiSandbox is designed to analyze suspicious files, URLs, and malware and is often integrated with broader enterprise security infrastructure, compromising these systems can provide attackers with a valuable foothold for further attacks. Threat actors could leverage the flaws to deploy web shells, execute malicious commands, harvest credentials, disable security controls, move laterally across networks, or install additional malware.

CISA added both vulnerabilities to the KEV Catalog on July 16, 2026, highlighting the urgency of remediation. Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to apply vendor-provided mitigations by July 19, 2026. Although there is no confirmed evidence linking these vulnerabilities to ransomware campaigns, their active exploitation, remote accessibility, and lack of authentication requirements significantly increase the risk of compromise, prompting organizations to prioritize remediation immediately.

Organizations are advised to promptly apply Fortinet's security updates and mitigation guidance across all affected environments, including FortiSandbox Cloud and FortiSandbox PaaS deployments. Security teams should identify and secure all internet-facing FortiSandbox instances, restrict access to management interfaces, monitor HTTP logs for suspicious or malformed requests, investigate unexpected command execution or unauthorized administrative accounts, and perform forensic triage to determine whether systems were compromised before patching. Where patches or mitigations are unavailable, organizations should follow Fortinet and CISA guidance or temporarily discontinue use of affected products until the risks have been addressed.

Impact

  • Gain Access

Indicators of Compromise

CVE

  • CVE-2026-39808

  • CVE-2026-25089

Remediation

  • Apply the latest Fortinet security updates for all affected FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS deployments immediately.
  • Prioritize remediation of CVE-2026-39808 and CVE-2026-25089, especially on internet-facing systems.
  • Restrict access to FortiSandbox management interfaces using firewalls, VPNs, or trusted IP allowlists.
  • Identify and inventory all exposed FortiSandbox assets to ensure no vulnerable systems are overlooked.
  • Review HTTP and application logs for malformed or suspicious requests that may indicate exploitation attempts.
  • Investigate unexpected command execution, new administrative accounts, or unauthorized configuration changes.
  • Perform forensic triage to determine whether affected systems were compromised before applying patches.
  • Monitor systems for indicators of compromise (IOCs), web shells, malware, or lateral movement activity.
  • Ensure FortiSandbox Cloud and FortiSandbox PaaS environments are updated and configured according to Fortinet's security guidance.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.