Skip to content
Vulnerability intelligence

CVE-2026-39813

Three chained vulnerabilities in FortiSandbox allow unauthenticated remote command execution at CVSS 9.1. Active exploitation confirmed. The devices purchased to protect legacy web infrastructure are now the entry point.

2026