Synced 29 Jul 2026 01:07 UTC Account
← FortiSandbox

FortiSandbox vulnerabilities: known CVEs & security history

Fortinet · Actively exploited · 60 tracked CVEs · 2 actively exploited · updated July 2026 · what is a CVE? →

This is the full list of known vulnerabilities (CVEs) across all FortiSandbox release lines — 60 in total, with 2 actively exploited in the wild. A CVE here doesn't mean your version is affected — check FortiSandbox's current status and the safe version to run.

60
known CVEs
2
actively exploited (KEV)
4
critical severity
0
ransomware-linked

Known FortiSandbox CVEs

Actively-exploited and most-severe first. Open any CVE for full details.

CVESeverityCVSSEPSSYear
CVE-2026-25089⚡ exploited critical 9.8 36% 2026
CVE-2026-39808⚡ exploited critical 9.8 49% 2026
CVE-2026-26083 critical 9.8 1% 2026
CVE-2026-39813 critical 9.8 17% 2026
CVE-2025-52436 high 8.8 6% 2026
CVE-2024-52961 high 8.8 1% 2025
CVE-2024-27778 high 8.8 1% 2025
CVE-2024-31491 high 8.8 1% 2024
CVE-2024-21756 high 8.8 2% 2024
CVE-2024-21755 high 8.8 2% 2024
CVE-2022-27487 high 8.8 1% 2023
CVE-2021-26097 high 8.8 1% 2021
CVE-2020-29011 high 8.8 1% 2021
CVE-2026-59835 high 8.6 0% 2026
CVE-2024-54027 high 8.2 0% 2025
CVE-2024-23671 high 8.1 1% 2024
CVE-2023-41682 high 8.1 1% 2023
CVE-2021-24010 high 8.1 1% 2021
CVE-2024-45328 high 7.8 0% 2025
CVE-2023-41843 high 7.5 0% 2023
CVE-2023-41681 high 7.5 0% 2023
CVE-2023-41680 high 7.5 0% 2023
CVE-2021-22124 high 7.5 1% 2021
CVE-2025-53949 high 7.2 16% 2025
CVE-2025-53679 high 7.2 11% 2025
CVE-2024-54018 high 7.2 9% 2025
CVE-2024-27781 high 7.1 25% 2025
CVE-2021-26105 medium 6.8 0% 2025
CVE-2026-25691 medium 6.7 0% 2026
CVE-2024-27779 medium 6.7 0% 2025
CVE-2023-47541 medium 6.7 0% 2024
CVE-2023-47540 medium 6.7 1% 2024
CVE-2022-27485 medium 6.5 1% 2023
CVE-2021-26096 medium 6.4 1% 2021
CVE-2021-22125 medium 6.3 1% 2021
CVE-2020-29014 medium 6.3 1% 2021
CVE-2018-1356 medium 6.1 1% 2019
CVE-2024-31487 medium 5.9 1% 2024
CVE-2022-26115 medium 5.9 0% 2023
CVE-2020-29012 medium 5.6 1% 2021
CVE-2025-61886 medium 5.4 0% 2026
CVE-2025-54353 medium 5.4 6% 2025
CVE-2022-22305 medium 5.4 0% 2023
CVE-2020-29013 medium 5.4 1% 2022
CVE-2021-24014 medium 5.4 1% 2021
CVE-2025-46215 medium 5.3 0% 2025
CVE-2021-32591 medium 5.3 1% 2021
CVE-2021-26098 medium 5.3 1% 2021
CVE-2026-39812 medium 4.8 0% 2026
CVE-2025-53608 medium 4.8 0% 2026
CVE-2024-54026 medium 4.3 0% 2025
CVE-2024-52960 medium 4.3 0% 2025
CVE-2024-31490 medium 4.3 0% 2024
CVE-2020-15939 medium 4.3 1% 2021
CVE-2025-67685 low 3.8 0% 2026
CVE-2022-30305 low 3.7 1% 2022
CVE-2023-45587 low 3.5 0% 2023
CVE-2023-41844 low 3.5 0% 2023
CVE-2023-41836 low 3.5 0% 2023
CVE-2026-27316 low 2.7 0% 2026

Is my FortiSandbox version affected?

The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.

Check your FortiSandbox version → · Monitor FortiSandbox for new CVEs →

FortiSandbox vulnerabilities — frequently asked

How many known vulnerabilities does FortiSandbox have?

IsItPatched tracks 60 CVEs for FortiSandbox, 2 of which are actively exploited (CISA KEV). 4 are critical-severity and 23 high-severity. These span every release line — what matters is whether the version you run is affected.

Does FortiSandbox have any actively-exploited vulnerabilities?

Yes — 2 FortiSandbox CVEs are in CISA's Known Exploited Vulnerabilities catalog, meaning they are confirmed exploited in the wild. Patch these as a priority.

What is the most severe FortiSandbox vulnerability?

Among tracked issues, CVE-2026-25089 (CRITICAL, CVSS 9.8), which is actively exploited, ranks highest — a OS command injection weakness.

Is FortiSandbox safe to use?

It depends on the version. The latest supported FortiSandbox release clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.

CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: FortiSandbox security status · FortiSandbox end-of-life · actively-exploited CVEs. Always verify against Fortinet's advisories — see our disclaimer.