Database/Control plane, storage & DevOps
Fortinet FortiSandbox: OS command injection via crafted HTTP requests
CVSS 9.8CVE-2026-39808Control plane, storage & DevOpsKnown exploitedcurated
Impact
OS command injection via crafted HTTP requests -> unauthenticated code execution
Who can reach it
Network (remote)
What to do
Control-plane: emergency firmware; same window as CVE-2026-25089
References
Related entries
- Fortinet FortiSandbox: OS command injectionCVE-2026-25089 · Fortinet FortiSandboxCritical
- VMware Avi Load Balancer: authentication bypass grants network access to the Avi control planeCVE-2026-47865 · VMware Avi Load Balancer (Avi Controller authentication)Critical
- rclone (rcd remote control server): An unauthenticated request to the rclone remote-control server instantiates aCVE-2026-49980 · rclone (rcd remote control server)Critical
- Proxmox VE (libpve-storage-perl XXE): XML external entity injection in the Proxmox storage library, reachableCVE-2026-51080 · Proxmox VE (libpve-storage-perl XXE)Critical
- Linux NFS server (nfsd, SECINFO_NO_NAME decode): A truncated SECINFO_NO_NAME operation leaves sin_exp uninitialized andCVE-2026-53398 · Linux NFS server (nfsd, SECINFO_NO_NAME decode)Critical
- Airflow FAB provider: Azure AD login accepted unsigned ID tokens, allowing login as AdminCVE-2026-59243 · Apache Airflow FAB auth manager (Azure AD OAuth ID token validation)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.