Vulnerability record · CVE-2026-25089 · published 9 June 2026
CVE-2026-25089: Fortinet FortiSandbox unauthenticated OS command injection
Fortinet · Fortisandbox
FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS fail to neutralize special elements in HTTP request handling, allowing OS command injection (CWE-78). The flaw is remotely reachable without authentication and carries a CVSS 3.1 base score of 9.8, so any exposed instance is a high-value target.
Description
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution with CVSS 9.8, confirmed KEV exploitation and a very high EPSS score makes this an urgent patch-first issue.
What it is
FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS fail to neutralize special elements in HTTP request handling, allowing OS command injection (CWE-78). The flaw is remotely reachable without authentication and carries a CVSS 3.1 base score of 9.8, so any exposed instance is a high-value target.
Impact
An unauthenticated attacker can execute arbitrary commands on the appliance, giving full control of the affected system and its data.
Attack surface
Reached over the network via specifically crafted HTTP requests to the FortiSandbox web interface; the CVSS vector shows no privileges and no user interaction required.
Exploitation
CVE-2026-25089 was added to CISA KEV on 2026-07-16 with a 2026-07-19 remediation due date, and EPSS gives a 30-day exploitation probability of 0.76112 (99.5th percentile), indicating active exploitation. No ransomware campaign use is documented.
What to do
- Apply the Fortinet PSIRT FG-IR-26-141 fix for FortiSandbox 5.0.x, 4.4.x, 4.2 and the Cloud/PaaS 5.0.4-5.0.5 deployments as directed by the vendor advisory.
- If a patch is not yet available for a given deployment, follow CISA BOD 26-04 guidance and discontinue use of the product or isolate it from untrusted networks.
- Remove internet exposure of FortiSandbox management and scanning interfaces; restrict access to trusted management networks only.
- Audit all FortiSandbox instances for signs of compromise before and after patching, given confirmed exploitation.
- Track the CISA KEV due date of 2026-07-19 and confirm remediation completion for every affected asset.
Detection
- Review FortiSandbox HTTP access and application logs for crafted requests containing shell metacharacters or command separators.
- Monitor for unexpected child processes spawned by the web service (for example shell, curl, wget or netcat) on FortiSandbox hosts.
- Alert on outbound network connections from FortiSandbox appliances to unfamiliar external hosts.
- Hunt for new or modified files, cron entries or accounts on FortiSandbox systems that do not match baseline configuration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-25089 to the Known Exploited Vulnerabilities catalog on 16 July 2026 as "Fortinet FortiSandbox OS Command Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 19 July 2026.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-141 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-25089 | US Government Resource |
Track CVE-2026-25089 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-25089), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.