Vulnerability intelligence
CVE-2026-25089
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
CVSS Score
9.1
Critical
EPSS — Exploit Probability
2.0%
Riskier than 84% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
2 articles across 2 outlets · first covered Jun 10, 2026 · latest Jun 10, 2026
Tracked incidents
Coverage timeline
-
Critical Vulnerabilities Patched in Fortinet, Ivanti Productswww.securityweek.com · Jun 10, 2026
-
FortiSandbox flaw CVE-2026-25089 lets attackers run commandssecurityonline.info · Jun 10, 2026