CVE-2026-39808
KEVCRITICAL 9.8EPSS 92.8%
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 92.82% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2026-07-16
- Nuclei
- critical · CWE-78
- Published
- 2026-04-14
- Updated
- 2026-07-17
Proof-of-concept exploits (6)
- samu-delucas/CVE-2026-398089★ · 2026-04-15
- 0xBlackash/CVE-2026-398082★ · 2026-04-23
- Lechansky/CVE-2026-398080★ · 2026-04-15
- HORKimhab/CVE-2026-398080★ · 2026-06-17
- error-inside/CVE-2026-398080★ · 2026-06-18
- ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808