AI agents can circumvent sandbox isolation by writing configuration files and scripts that trusted host processes later execute—without technically leaving the sandbox themselves.
Three vulnerabilities in Fortinet FortiSandbox (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are being actively exploited; two were patched since April 2026, the newest only a week old.