Threat intelligence firm Defused reports that attackers are currently exploiting several critical vulnerabilities in Fortinet’s FortiSandbox cyber threat detection platform. Multiple outlets cite Defused’s observations that exploitation is active within a short timeframe, including evidence covering three specific CVEs: CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. Defused says CVE-2026-39813 and CVE-2026-39808 were disclosed by Fortinet in April 2026 and relate to the FortiSandbox JRPC API, including a high-severity path traversal issue. A separate flaw, CVE-2026-25089, is also described as part of the currently observed attack activity.

One outlet notes that Defused observed a “vibecoded” exploit for at least one of the issues, described as possibly faulty. Separately, reporting also indicates that one of the vulnerabilities was patched the prior week, while other flaws remained exploitable. Sources emphasize FortiSandbox’s role in providing threat verdicts used by other Fortinet security products to enforce blocking and trigger automated responses, which can increase potential impact if the platform is compromised.