← Vulnerability feed

Vulnerability record · CVE-2026-25089 · published 9 June 2026

CVE-2026-25089: Fortinet FortiSandbox unauthenticated OS command injection

Fortinet · Fortisandbox

FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS fail to neutralize special elements in HTTP request handling, allowing OS command injection (CWE-78). The flaw is remotely reachable without authentication and carries a CVSS 3.1 base score of 9.8, so any exposed instance is a high-value target.

9.8 CVSS 3.1 Critical CISA KEV since 16 Jul 2026 EPSS 76% · top 0.5% CWE-78 · OS command injection
9.8CVSS 3.1 base score
76%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
2References
23 Jul 2026Last modified by NVD

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with CVSS 9.8, confirmed KEV exploitation and a very high EPSS score makes this an urgent patch-first issue.

What it is

FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS fail to neutralize special elements in HTTP request handling, allowing OS command injection (CWE-78). The flaw is remotely reachable without authentication and carries a CVSS 3.1 base score of 9.8, so any exposed instance is a high-value target.

Impact

An unauthenticated attacker can execute arbitrary commands on the appliance, giving full control of the affected system and its data.

Attack surface

Reached over the network via specifically crafted HTTP requests to the FortiSandbox web interface; the CVSS vector shows no privileges and no user interaction required.

Exploitation

CVE-2026-25089 was added to CISA KEV on 2026-07-16 with a 2026-07-19 remediation due date, and EPSS gives a 30-day exploitation probability of 0.76112 (99.5th percentile), indicating active exploitation. No ransomware campaign use is documented.

What to do

  • Apply the Fortinet PSIRT FG-IR-26-141 fix for FortiSandbox 5.0.x, 4.4.x, 4.2 and the Cloud/PaaS 5.0.4-5.0.5 deployments as directed by the vendor advisory.
  • If a patch is not yet available for a given deployment, follow CISA BOD 26-04 guidance and discontinue use of the product or isolate it from untrusted networks.
  • Remove internet exposure of FortiSandbox management and scanning interfaces; restrict access to trusted management networks only.
  • Audit all FortiSandbox instances for signs of compromise before and after patching, given confirmed exploitation.
  • Track the CISA KEV due date of 2026-07-19 and confirm remediation completion for every affected asset.

Detection

  • Review FortiSandbox HTTP access and application logs for crafted requests containing shell metacharacters or command separators.
  • Monitor for unexpected child processes spawned by the web service (for example shell, curl, wget or netcat) on FortiSandbox hosts.
  • Alert on outbound network connections from FortiSandbox appliances to unfamiliar external hosts.
  • Hunt for new or modified files, cron entries or accounts on FortiSandbox systems that do not match baseline configuration.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-25089 to the Known Exploited Vulnerabilities catalog on 16 July 2026 as "Fortinet FortiSandbox OS Command Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 19 July 2026.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-25089 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-39808Fortinet FortiSandbox OS command injectionFortiSandbox 4.4.0 through 4.4.8 fails to neutralize special elements used in OS commands, allowing command injection. The flaw is remotely reachable…KEVEPSS 47%analysed9.8CVE-2026-26083Fortinet fortisandbox missing authorization vulnerabilityA missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 throug…EPSS 0.50%9.8CVE-2026-39813Fortinet fortisandbox vulnerabilityA path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to esc…EPSS 0.72%9.6CVE-2025-52436Fortinet fortisandbox cross-site scripting vulnerabilityAn Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox…EPSS 6.5%9.0CVE-2024-27781Fortinet fortisandbox cross-site scripting vulnerabilityAn improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, F…EPSS 28%8.8CVE-2025-53949Fortinet fortisandbox os command injection vulnerabilityAn Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiS…EPSS 17%8.8CVE-2021-26105Fortinet fortisandbox out-of-bounds write vulnerabilityA stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allo…EPSS 0.50%8.8CVE-2024-54026Fortinet fortisandbox sql injection vulnerabilityAn improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2026-25089), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.