securityaffairs.com 6/11/2026, 10:31:52 AM · external

Fortinet patches CVE-2026-25089 in FortiSandbox command injection

Fortinet patches CVE-2026-25089 in FortiSandbox command injection
Developing story vulnerability 2 articles tracked
Multiple critical vulnerabilities disclosed in Ivanti Sentry and Fortinet products
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

FORTINET has released patches for a critical vulnerability in its FortiSandbox products, specifically CVE-2026-25089, which has a CVSS score of 9.8. This OS command injection flaw allows unauthenticated attackers to execute arbitrary commands through specially crafted HTTP requests. The affected versions include FortiSandbox 5.0.0 to 5.0.5, 4.4.0 to 4.4.8, and certain versions of FortiSandbox Cloud and PaaS.

In addition, two medium-severity vulnerabilities were addressed affecting FortiOS, FortiProxy, and FortiPortal. Fortinet advises users to apply the security updates as there are no known exploitations of these vulnerabilities in the wild.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline