Thursday, August 27, 2026

Fortinet Fixes 11 Security Flaws Affecting FortiSandbox, FortiOS, FortiAnalyzer, and FortiManager

Fortinet has recently released a comprehensive security update, patching 11 newly identified vulnerabilities across several of its core enterprise products.

The security flaws affect critical infrastructure components, including FortiSandbox, FortiOS, FortiAnalyzer, and FortiManager.

Addressing these vulnerabilities is paramount for organizations relying on these solutions to maintain robust network security and prevent potential unauthorized access or data breaches.

The latest advisories, coordinated by the Fortinet Product Security Incident Response Team (PSIRT), highlight the company’s proactive approach to identifying and mitigating security risks.

Two of the 11 patched vulnerabilities have been classified as critical, demanding immediate attention from network administrators and security professionals to secure their environments.

Critical Vulnerabilities Threaten Enterprise Security

Among the resolved issues, the two most severe vulnerabilities pose significant risks to enterprise networks:

  • OS Command Injection (CVE-2026-39808): This critical flaw in the FortiSandbox and FortiSandbox PaaS API endpoint allows unauthenticated attackers to execute arbitrary OS commands. By improperly neutralizing special elements, threat actors could gain complete control over the affected system, making it a high-priority target for remediation.
  • Authentication Bypass and Privilege Escalation (CVE-2026-39813): Found in the FortiSandbox JRPC API, this critical path traversal vulnerability enables an unauthenticated attacker to bypass authentication mechanisms and escalate their privileges. This flaw could lead to severe internal compromise and unauthorized administrative access.

The remaining nine vulnerabilities range from high to low severity, affecting various components and attack vectors:

  • High-severity heap-based buffer overflows, such as CVE-2026-22828 in the FortiAnalyzer Cloud and FortiManager Cloud oftpd daemon, could allow unauthenticated attackers to crash systems or execute malicious code.
  • Medium-severity flaws include multiple instances of path traversal (CVE-2025-68649, CVE-2025-61624), stored and reflected Cross-Site Scripting (XSS), and SQL injection via JSON RPC API.
  • Missing authentication for critical functions (CVE-2025-53847) in FortiOS and FortiSwitchManager further exposes networks to unauthenticated internal attacks.

Complete List of Addressed Vulnerabilities

Below is the complete table data detailing all 11 vulnerabilities addressed in the April 14, 2026, PSIRT advisories:

CVE IDVulnerability DescriptionAffected ProductsSeverityAttack Type
CVE-2026-39808OS Command Injection through API endpointFortiSandbox, FortiSandbox PaaSCriticalUnauthenticated
CVE-2026-39813Unauthenticated Authentication bypass and Privilege escalationFortiSandboxCriticalUnauthenticated
CVE-2026-22828Heap-based buffer overflow in oftpd daemonFortiAnalyzer Cloud, FortiManager CloudHighUnauthenticated
CVE-2026-25691Arbitrary directory delete on vmimages delete featureFortiSandbox, FortiSandbox Cloud, FortiSandbox PaaSMediumAuthenticated
CVE-2025-53847Missing Authentication for critical function in CAPWAP daemonFortiOS, FortiSwitchManagerMediumUnauthenticated
CVE-2026-39812Multiple Stored XSSFortiSandbox, FortiSandbox PaaSMediumAuthenticated
CVE-2025-68649Path Traversal in CLIFortiAnalyzer, FortiManagerMediumAuthenticated
CVE-2025-61624Path Traversal in CLIFortiOS, FortiPAM, FortiProxy, FortiSwitchManagerMediumAuthenticated
CVE-2025-61886Reflected XSS in Operation CenterFortiSandbox, FortiSandbox PaaSMediumUnauthenticated
CVE-2025-61848SQL Injection via JSON RPC APIFortiAnalyzer, FortiManagerMediumAuthenticated
CVE-2026-27316Credential disclosure in LDAP configuration web pageFortiSandbox, FortiSandbox PaaSLowAuthenticated

Mitigation and Remediation Strategies

Organizations are strongly urged to review the Fortinet PSIRT advisories and apply the necessary updates immediately to secure their infrastructure. Key mitigation steps include:

  • Upgrading to the latest patched firmware versions provided by Fortinet for all affected products.
  • Reviewing system logs and monitoring network traffic for any signs of exploitation attempts, particularly targeting the exposed API endpoints.
  • Restricting external access to critical management interfaces and ensuring strict access controls are enforced.

Network administrators should utilize the official Fortinet Upgrade Path Tool to ensure a smooth transition to the patched versions while maintaining system stability.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power

AI infrastructure is rapidly becoming a high-value enterprise attack...

Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations

A Russian-speaking affiliate of the Aurora ransomware operation compromised...

CISA Warns of Actively Exploited Microsoft SQL Server RCE Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale

Menlo Park, California, USA, August 27th, 2026, CyberNewswire AccuKnox today...

Related Articles

Recent News