FortiSandbox CVE-2026-39808 OS Command Injection Attempt
Detects incoming HTTP requests to a FortiSandbox device that contain suspicious command injection patterns. The rule monitors both the URI and the request body for shell metacharacters such as ';', '|', '`', '$(', or '&&', followed by common binary execution commands (e.g., cat, wget, curl, bash, rm). This behavior is indicative of an exploit attempt targeting CVE-2026-39808.
Suricata

