CVE-2026-39808
CRITICAL
CVSS: 9.8
EPSS: 92.8%
VulnCheck KEV
PoC Available
CWE-78
T1059
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Published: 2026-04-14