← back
CVE-2026-39813criticalobserved exploitationCWE-24

CVE-2026-39813

75Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 9.1epss 23%
from disclosure to weapon9 days
Published on NVDApr 14
1st PoC+9d
VulnCheck+62d
exploitation probability
23%top 2% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.