Critical severity9.8CISA KEVNVD Advisory· Published Jun 9, 2026· Updated Jun 11, 2026
CVE-2026-25089
CVE-2026-25089
Description
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*range: >=4.2.0,<=4.2.8
- cpe:2.3:a:fortinet:fortisandbox_cloud:*:*:*:*:*:*:*:*range: >=5.0.4,<5.0.6
- cpe:2.3:a:fortinet:fortisandbox_paas:*:*:*:*:*:*:*:*range: >=5.0.4,<5.0.6
- (no CPE)range: >=4.2, <=5.0.5
Patches
Vulnerability mechanics
References
1- fortiguard.fortinet.com/psirt/FG-IR-26-141nvdVendor Advisory
News mentions
25- July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall FlawsCyber Security News · Jul 23, 2026
- New InfraTrust report reveals infrastructure flaws admins should patch firstBleepingComputer · Jul 22, 2026
- CISA Adds FortiSandbox Bugs to KEV CatalogGovInfoSecurity · Jul 18, 2026
- Attackers target critical FortiSandbox flaws as CISA issues patch orderThe Register Security · Jul 17, 2026
- CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet VulnerabilitiesInfosecurity Magazine · Jul 17, 2026
- Fresh SharePoint Vulnerability Exploited Soon After DisclosureSecurityWeek · Jul 17, 2026
- CISA urges immediate action on actively exploited Fortinet flawsBleepingComputer · Jul 17, 2026
- CISA Warns of Fortinet FortiSandbox OS Injection Vulnerabilities Exploited in AttacksCyber Security News · Jul 17, 2026
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEVThe Hacker News · Jul 17, 2026
- Fortinet: 2 Actively-Exploited Flaws Added to CISA KEVVypr Intelligence · Jul 16, 2026
- FortiSandbox Vulnerability Allows Attackers to Access VNC Servers of VMsCyber Security News · Jul 14, 2026
- 22nd June – Threat Intelligence ReportCheck Point Research · Jul 1, 2026
- Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attackHelp Net Security · Jun 21, 2026
- Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in AprilCyberScoop · Jun 17, 2026
- 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker CrosshairsSecurityWeek · Jun 17, 2026
- Three critical Fortinet sandbox bugs splattered by unknown attackersThe Register Security · Jun 16, 2026
- Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in AttacksCyber Security News · Jun 16, 2026
- Attackers are exploiting FortiSandbox vulnerabilitiesHelp Net Security · Jun 16, 2026
- Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last WeekThe Hacker News · Jun 16, 2026
- Critical Fortinet FortiSandbox flaws now exploited in attacksBleepingComputer · Jun 16, 2026
- Ivanti, Fortinet, and SAP Release Patches for Multiple Critical VulnerabilitiesThe Hacker News · Jun 10, 2026
- Critical Vulnerabilities Patched in Fortinet, Ivanti ProductsSecurityWeek · Jun 10, 2026
- Fortinet: Critical Command Injection and Other Flaws Disclosed TogetherVypr Intelligence · Jun 9, 2026
- Fortinet FortiSandbox Vulnerability Allows Attackers to Execute Unauthorized CommandsCyber Security News · Jun 9, 2026
- CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA Alerts