CRITICAL: Three FortiSandbox Flaws Under Active Exploitation as Attackers Chain Auth Bypass and Command Injection
Three critical FortiSandbox vulnerabilities are under active exploitation, led by CVE-2026-39813, a path traversal flaw in the JRPC API that lets unauthenticated attackers bypass authentication via crafted HTTP requests. Paired with two OS command injection bugs, the chain gives remote code execution on appliances running FortiSandbox 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8. Upgrade to 5.0.6 or 4.4.9 immediately.