A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
https://www.helpnetsecurity.com/2026/04/16/fortinet-fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808/
https://www.theregister.com/2026/04/15/critical_fortinet_sandbox_bugs/
https://www.securityweek.com/fortinet-patches-critical-fortisandbox-vulnerabilities/
https://thehackernews.com/2026/04/april-patch-tuesday-fixes-critical.html
https://fortiguard.fortinet.com/psirt/FG-IR-26-100
Source: Mitre, NVD
Published: 2026-04-14
Updated: 2026-04-14
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.00292