Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808)

2026-04-16T14:51:49Z5e1991b6c64e467060a5b7c8d06b3727c72a5cc68f5b0442c6da03a2aa667a43
androidauthentication-bypasscargo-theftcve-2026-39808cve-2026-39813fortinetfortisandboxfraudgoogle-playgoogle-play-policynorth-koreapatchprivacyproofpointremote-code-executiontailsthreat-actortorunauthenticatedvulnerability

What happened

The feed highlights critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808) that allow unauthenticated attackers to bypass authentication and execute unauthorized code or commands via specially crafted HTTP requests — Fortinet has released fixes and organizations should patch affected FortiSandbox deployments immediately. Other items in the feed cover Google Play policy changes restricting contacts and location access for apps, an emergency Tails 7.6.2 release fixing a file-exposure bug, Proofpoint analysis of a cargo-theft malware actor monitored for over a month inside a decoy

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
5e1991b6c64e467060a5b7c8d06b3727c72a5cc68f5b0442c6da03a2aa667a43
Enrichment time
2026-04-16T14:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808) · Baitaphish