Three unauthenticated remote code execution flaws in Fortinet FortiSandbox (CVE 2026 39813, CVE 2026 39808, CVE 2026 25089) are under active attack as of June 16, 2026, all carrying a CVSS score of 9.1 [8][17]. One exploit, targeting CVE 2026 25089, is described as 'vibecoded' — likely AI generated and faulty — offe...
Research answer

Create a landscape editorial hero image for this Studio Global article: What are the three critical Fortinet FortiSandbox vulnerabilities being actively exploited as of mid-June 2026, what are their CVSS scores a. Article summary: Here is the full picture based on the latest reporting as of mid-June 2026.. Topic tags: general, government, general web, user generated. Reference image context from search candidates: Reference image 1: visual subject "Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclos" source context "Ivanti, Fortinet, and SAP Release Patches for Multiple Critical ..." Reference image 2: visual subject "Photo by THECYBERTHRONE on April 16, 2026. May be an image of text that says 'FORTINET FortiSandbox CRITICAL VULNERABILITY ADVISORY !'. Fortinet
Threat intelligence firm Defused reported on June 16, 2026, that three critical vulnerabilities in Fortinet's FortiSandbox malware analysis platform are being actively exploited within a 24-hour window . The flaws enable unauthenticated remote code execution and authentication bypass on a product that many downstream Fortinet security appliances trust to verdict malware. Adding a novel dimension to the threat, one of the exploits is suspected to be AI-generated, illustrating both the accelerating pace of weaponization and the current limitations of machine-written attack code.
All three vulnerabilities were assigned a CVSS score of 9.1, placing them firmly in the critical-severity zone that demands immediate remediation .
A note on CVSS scoring: While a few early sources initially listed CVE-2026-39808 and CVE-2026-39813 with a CVSS score of 9.8 , the authoritative mid-June reporting from NVD, Defused, BleepingComputer, and The Hacker News consistently confirms a 9.1 rating for all three CVEs
. Security teams should use the 9.1 score to align with current threat intelligence.
Defused reported that the exploit targeting CVE-2026-25089 appears to be "vibecoded" — a term indicating the code is likely AI-generated or hastily assembled, lacking the polish and reliability of a hand-crafted professional exploit .
This observation provides a rare window into how AI is changing the economics of vulnerability exploitation:
The three FortiSandbox vulnerabilities are unauthenticated, low-complexity, and require no user interaction — making them ideal candidates for automated scanning and mass exploitation . FortiSandbox is particularly sensitive because other Fortinet products, including firewalls and endpoint detection systems, may rely on its malware verdicts to trigger automated blocking decisions
.
No customer impact or attribution to a specific threat group has been confirmed as of June 16, 2026, but the window between patch release and active, in-the-wild exploitation underscores the urgency for organizations to treat these 9.1-rated flaws as top-priority incidents .
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Three unauthenticated remote code execution flaws in Fortinet FortiSandbox (CVE 2026 39813, CVE 2026 39808, CVE 2026 25089) are under active attack as of June 16, 2026, all carrying a CVSS score of 9.1 [8][17].
Three unauthenticated remote code execution flaws in Fortinet FortiSandbox (CVE 2026 39813, CVE 2026 39808, CVE 2026 25089) are under active attack as of June 16, 2026, all carrying a CVSS score of 9.1 [8][17]. One exploit, targeting CVE 2026 25089, is described as 'vibecoded' — likely AI generated and faulty — offering a real world case study in how AI lowers the barrier for attackers while introducing noisy, inconsistent c...
The flaws affect on premise and cloud versions of FortiSandbox, a platform other Fortinet security products rely on for threat verdicts.