Fortinet Faces New Scrutiny After CISA Flags Critical FortiSandbox Flaws Amid Ongoing Credential Leak Campaign
Thu, September 03, 2026Fortinet (NASDAQ: FTNT) finds itself at the center of heightened security concerns following two significant developments disclosed in recent weeks. The Cybersecurity and Infrastructure Security Agency (CISA) added two FortiSandbox vulnerabilities—CVE‑2026‑25089 and CVE‑2026‑39808—to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation. Meanwhile, the fallout continues from the FortiBleed campaign, which exposed credentials for tens of thousands of FortiGate firewalls and VPNs.
CISA Flags FortiSandbox Flaws as Actively Exploited
On July 16, 2026, CISA moved two critical FortiSandbox command‑injection vulnerabilities to its KEV list, indicating confirmed active attacks. This triggered a mandatory patch deadline of July 19 for U.S. federal civilian agencies under Binding Operational Directive 26‑04. The flaws, CVE‑2026‑25089 and CVE‑2026‑39808, carry high severity ratings (CVSS 9.1), allowing unauthenticated remote code execution via specially crafted HTTP requests. Although Fortinet patched the issues in April and June, research firm Defused detected exploitation attempts, and CISA’s inclusion confirms the urgency of remediation. Fortinet has not updated its advisories to reflect confirmed exploitation.
The inclusion in the KEV catalog compels federal agencies to patch or otherwise mitigate the vulnerabilities by the deadline. This development brings renewed focus to Fortinet’s FortiSandbox product amid scrutiny over patching timelines and administrative practices.
FortiBleed: Credential Leak Crisis Persists
Simultaneously, the FortiBleed campaign continues to reverberate across the cybersecurity landscape. Reports indicate that around 74,000 FortiGate devices—spanning firewalls and VPN gateways—have had credentials exposed through automated brute‑force and credential‑stuffing attacks, leveraging previously leaked passwords. The incident affects an estimated 75,000 devices across 194 countries, with notable organizations such as Accenture, Lenovo, Oracle, and federal entities implicated.
Fortinet emphasized that the campaign did not involve a new vulnerability but rather relied on weak password hygiene and reused or previously compromised credentials. Nonetheless, the scale and persistence of the incident spotlight operational vulnerabilities and elevate concerns over endpoint security postures.
Implications for Fortinet Stock and Trust
Fortinet shares, trading most recently at $154.54 with a 4.72% decline as of September 2, 2026, may face pressure amid these dual developments. The confluence of active exploitation and widespread credential exposure raises heightened risk perceptions. However, attributing stock moves directly to these events requires caution absent clear financial reporting linking share price fluctuations to security developments.
Operationally, this period could catalyze renewed attention among enterprise customers and government clients toward product security and patching policies. Fortinet’s leadership faces a critical test in reinforcing trust, ensuring timely security updates, and guiding its customer base through effective remediation strategies.
What’s Next
Addition of the sandbox vulnerabilities to CISA’s KEV list is a serious escalation. Observers will monitor whether Fortinet updates its advisories to explicitly acknowledge active exploitation and provide customers with clearer guidance and support. Agencies and organizations must ensure vulnerable FortiSandbox deployments are promptly patched.
On the FortiBleed front, widespread credential hygiene remains paramount. Fortinet’s emphasis on credential resets and administrative best practices underscores the need for proactive security procedures. Customers should treat exposed devices as compromised and rotate credentials comprehensively, implement MFA, and reduce management interface exposure.
For investors tracking FTNT, the company’s handling of security incidents could prove pivotal for market confidence. Watch for subsequent statements from Fortinet, updates in customer remediation guidance, and any shifts in analyst sentiment or customer retention metrics.