Threat intelligence firm Defused Cyber warns that cybercriminals are actively exploiting several serious security flaws in Fortinet FortiSandbox.
In one posts on X The company stated that in the last 24 hours they have observed attacks exploiting the vulnerabilities CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089.
CVE-2026-39813, which has a CVSS score of 9.1, is a path traversal vulnerability in FortiSandbox JRPC API. The flaw could allow an unauthenticated attacker to bypass authentication through specially crafted HTTP requests.
The second vulnerability, CVE-2026-39808, which also has a CVSS score of 9.1, is a command injection vulnerability in the operating system. It could allow an unauthenticated attacker to execute arbitrary code or commands via specially crafted HTTP requests. Both of these vulnerabilities were patched by Fortinet in April 2026.
The third vulnerability, CVE-2026-25089, was first patched last week. Fortinet describes it as a command injection that affects FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS Web UI. The flaw could allow an unauthenticated attacker to execute unauthorized commands via specially crafted HTTP requests.
According to Defused Cyber, there are signs that the proof-of-concept material circulating around CVE-2026-25089 has been partly generated using artificial intelligence. The company also believes that the material contains inaccuracies and points out that no working exploit has yet been published.
Fortinet continues to be an attractive target
Vulnerabilities in Fortinet security products have become recurring targets for cybercriminal groups in recent years.
In April 2026, Fortinet released emergency security updates for the critical vulnerability CVE-2026-35616 in FortiClient EMS. The company then confirmed that the vulnerability was already being exploited in real attacks.
FortiBleed reportedly compromised over 30,000 firewalls
Meanwhile, the cybersecurity company reports SOCRadar that suspected Russian-speaking threat actors have compromised more than 30,000 Fortinet firewalls in a massive global campaign.
The discovery was made after researchers identified an active server linked to the operation.
According to SOCRadar The attackers' database contains login details for over 30,791 devices belonging to companies, governments and organizations in 194 countries.
The company describes the data as verified and working usernames and passwords that have been tested and confirmed through automated tools that run continuously.
Among the affected organizations are banks, telecom operators, hospitals, universities, government agencies, energy companies and multinational corporations.
The ten hardest-hit countries includes India, USA, Mexico, Colombia, Thailand, Taiwan, Indonesia, Malaysia, Singapore and France. India According to the report, it accounts for around 60 percent of all internet-exposed Fortinet installations in the public sector.
Two-step method for expanding the intrusion
SOCRadar states that the attackers use a two-step method.
First, previously leaked ones are tested Fortinet password against internet-exposed devices. According to the company, many organizations have never changed passwords after previous data breaches.
Once attackers gain access to a device, they passively monitor network traffic to collect additional credentials passing through the system, which they then use to compromise more devices and expand their operation.
Hudson Rock: Nearly 74,000 firewall URLs have been attacked
In a follow-up analysis published on June 17, 2026, cybersecurity firm Hudson Rock states that the so-called The FortiBleed campaign has targeted 73,932 unique firewall URLs in 194 countries.
According to the company, the campaign resulted in 21,632 unique affected domains.
The activity was first noticed by the security researcher Volodymyr “Bob” Diachenko in a post on LinkedIn last week.

According to Diachenko It involves a Russian-speaking group with several operators conducting large-scale collection of authentication data from Fortinet FortiGate SSL VPN devices worldwide.
The operation reportedly made approximately 1.16 billion authentication attempts against 320,777 FortiGate targets and another 2.1 billion attempts against 163,650 Microsoft SQL servers.
Intercepts VPN traffic and attacks Active Directory
The researchers assess that the group's activities extend far beyond traditional collection of usernames and passwords.
According to the analysis, the attackers intercept SSL VPN authentication, crack hash values using a cluster of 45 GPUs managed via Hashtopolis, and then move further into internal Active Directory environments to establish long-term access.
It is also suspected that the attackers are systematically scanning internet-exposed Fortinet installations using known password lists and recording all successful logins.
Compromised devices are then used as listening points to capture additional credentials, which, according to the researchers, creates a continuous chain of unauthorized access.
Hudson Rock warns in particular that even very complex passwords can become useless if exposed in plaintext.
“Complexity is completely neutralized when passwords are reset in clear text. If attackers can reuse known credentials to bypass the security perimeter, the password policy itself offers no protection,” the company notes.








