Fortinet has recently released a comprehensive security update, patching 11 newly identified vulnerabilities across several of its core enterprise products.
The security flaws affect critical infrastructure components, including FortiSandbox, FortiOS, FortiAnalyzer, and FortiManager.
Addressing these vulnerabilities is paramount for organizations relying on these solutions to maintain robust network security and prevent potential unauthorized access or data breaches.
The latest advisories, coordinated by the Fortinet Product Security Incident Response Team (PSIRT), highlight the company’s proactive approach to identifying and mitigating security risks.
Two of the 11 patched vulnerabilities have been classified as critical, demanding immediate attention from network administrators and security professionals to secure their environments.
Critical Vulnerabilities Threaten Enterprise Security
Among the resolved issues, the two most severe vulnerabilities pose significant risks to enterprise networks:
- OS Command Injection (CVE-2026-39808):Â This critical flaw in the FortiSandbox and FortiSandbox PaaS API endpoint allows unauthenticated attackers to execute arbitrary OS commands. By improperly neutralizing special elements, threat actors could gain complete control over the affected system, making it a high-priority target for remediation.
- Authentication Bypass and Privilege Escalation (CVE-2026-39813):Â Found in the FortiSandbox JRPC API, this critical path traversal vulnerability enables an unauthenticated attacker to bypass authentication mechanisms and escalate their privileges. This flaw could lead to severe internal compromise and unauthorized administrative access.
The remaining nine vulnerabilities range from high to low severity, affecting various components and attack vectors:
- High-severity heap-based buffer overflows, such as CVE-2026-22828 in the FortiAnalyzer Cloud and FortiManager Cloud oftpd daemon, could allow unauthenticated attackers to crash systems or execute malicious code.
- Medium-severity flaws include multiple instances of path traversal (CVE-2025-68649, CVE-2025-61624), stored and reflected Cross-Site Scripting (XSS), and SQL injection via JSON RPC API.
- Missing authentication for critical functions (CVE-2025-53847) in FortiOS and FortiSwitchManager further exposes networks to unauthenticated internal attacks.
Complete List of Addressed Vulnerabilities
Below is the complete table data detailing all 11 vulnerabilities addressed in the April 14, 2026, PSIRT advisories:
| CVE ID | Vulnerability Description | Affected Products | Severity | Attack Type |
|---|---|---|---|---|
| CVE-2026-39808 | OS Command Injection through API endpoint | FortiSandbox, FortiSandbox PaaS | Critical | Unauthenticated |
| CVE-2026-39813 | Unauthenticated Authentication bypass and Privilege escalation | FortiSandbox | Critical | Unauthenticated |
| CVE-2026-22828 | Heap-based buffer overflow in oftpd daemon | FortiAnalyzer Cloud, FortiManager Cloud | High | Unauthenticated |
| CVE-2026-25691 | Arbitrary directory delete on vmimages delete feature | FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS | Medium | Authenticated |
| CVE-2025-53847 | Missing Authentication for critical function in CAPWAP daemon | FortiOS, FortiSwitchManager | Medium | Unauthenticated |
| CVE-2026-39812 | Multiple Stored XSS | FortiSandbox, FortiSandbox PaaS | Medium | Authenticated |
| CVE-2025-68649 | Path Traversal in CLI | FortiAnalyzer, FortiManager | Medium | Authenticated |
| CVE-2025-61624 | Path Traversal in CLI | FortiOS, FortiPAM, FortiProxy, FortiSwitchManager | Medium | Authenticated |
| CVE-2025-61886 | Reflected XSS in Operation Center | FortiSandbox, FortiSandbox PaaS | Medium | Unauthenticated |
| CVE-2025-61848 | SQL Injection via JSON RPC API | FortiAnalyzer, FortiManager | Medium | Authenticated |
| CVE-2026-27316 | Credential disclosure in LDAP configuration web page | FortiSandbox, FortiSandbox PaaS | Low | Authenticated |
Mitigation and Remediation Strategies
Organizations are strongly urged to review the Fortinet PSIRT advisories and apply the necessary updates immediately to secure their infrastructure. Key mitigation steps include:
- Upgrading to the latest patched firmware versions provided by Fortinet for all affected products.
- Reviewing system logs and monitoring network traffic for any signs of exploitation attempts, particularly targeting the exposed API endpoints.
- Restricting external access to critical management interfaces and ensuring strict access controls are enforced.
Network administrators should utilize the official Fortinet Upgrade Path Tool to ensure a smooth transition to the patched versions while maintaining system stability.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





