CISA KEV 警告 26/07/16:Fortinet FortiSandbox の脆弱性 CVE-2026-39808/25089 を KEV に登録

CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands

2026/07/17 gbhackers — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Fortinet の FortiSandbox に存在する 2 件の深刻な脆弱性 CVE-2026-39808CVE-2026-25089 を、Known Exploited Vulnerabilities (KEV) カタログに追加した。これらの脆弱性は、OS コマンド・インジェクションの脆弱性 (CWE-78) に起因し、影響を受けるシステム上での不正なコマンド実行に悪用されている。影響が及ぶ製品の範囲は、FortiSandbox Cloud/FortiSandbox PaaS などの FortiSandbox の導入環境となる。

Continue reading “CISA KEV 警告 26/07/16:Fortinet FortiSandbox の脆弱性 CVE-2026-39808/25089 を KEV に登録”

FortiSandbox の脆弱性 CVE-2026-39808 が FIX:PoC エクスプロイトも公開

PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands

2026/04/18 CyberSecurityNews — Fortinet の FortiSandbox 製品群の、深刻な脆弱性 CVE-2026-39808 に対する PoC エクスプロイトが公開された。この脆弱性を悪用する未認証の攻撃者は、ログイン資格情報を必要とせずに、root 権限で任意の OS コマンドの実行が可能になる。FortiSandbox に影響を及ぼす OS コマンド・インジェクションの脆弱性 CVE-2026-39808 は、”/fortisandbox/job-detail/tracer-behavior” エンドポイントに存在する。

Continue reading “FortiSandbox の脆弱性 CVE-2026-39808 が FIX:PoC エクスプロイトも公開”

Fortinet の 11 件の脆弱性が FIX:FortiSandbox/FortiOS/FortiAnalyzer/FortiManager に影響

Fortinet Patches 11 Vulnerabilities Across FortiSandbox, FortiOS, FortiAnalyzer, and FortiManager

2026/04/14 CyberSecurityNews — 2026年4月14日に Fortinet が公表したのは、11 件の脆弱性に対応する包括的なセキュリティ・アドバイザリであり、その内訳は Critical が 2 件、High が 2 件、Medium および Low が 7 件となっている。これらの脆弱性が影響を及ぼす範囲は、FortiSandbox/FortiAnalyzer/FortiManager/FortiOS/FortiProxy/FortiPAM/FortiSwitchManager である。エンタープライズ管理者に対して強く求められるのは、優先的かつ即時のパッチ適用である。

Continue reading “Fortinet の 11 件の脆弱性が FIX:FortiSandbox/FortiOS/FortiAnalyzer/FortiManager に影響”