Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

CVE-2026-39808 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-39808 | CVSS 9.8 (Critical) | Exploit: PoC available

What Is It

CVE-2026-39808 is an OS command injection vulnerability affecting Fortinet FortiSandbox versions 4.4.0 through 4.4.8 through an attack vector that has not been specified in the available vulnerability description.

Technical Detail

The flaw results from improper neutralization of special elements used in operating system commands. An attacker able to reach the vulnerable input path may be able to inject and execute unauthorized commands or code on the FortiSandbox system. The available information does not confirm whether exploitation requires authentication, the affected interface, or the execution privileges obtained.

Exploitation Status

A proof of concept is available. CVE-2026-39808 is not listed in CISA's Known Exploited Vulnerabilities Catalog as of August 17, 2026, and active exploitation has not been confirmed.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Treat this as a critical patching priority and update affected Fortinet FortiSandbox appliances to a vendor-fixed release as soon as Fortinet makes one available or identifies a supported remediation path. Review Fortinet security advisories for confirmed affected interfaces, authentication requirements, and any available temporary mitigations. Until remediation is complete, restrict access to FortiSandbox management and service interfaces to trusted administrative networks, minimize exposed services, and monitor appliance and surrounding network logs for unexpected command execution, unusual child processes, configuration changes, or anomalous outbound connections. Specific detection indicators and workaround details have not yet been confirmed in the available data.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →