CVE-2026-25089 — Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Platform
FortiGate / FortiOS
CVE Record
CVE-2026-25089
Advisory
CISA-KEV
Published
16 July 2026
Views
40
Primary source: Review the official advisory at nvd.nist.gov
Go to Source
Status
Bu açık CISA tarafından aktif istismar edildiği doğrulanmış açıklar katalogunda yer alıyor. Teorik bir risk değil — sahada kullanılıyor.
Description
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Details
Vendor: Fortinet
Product: FortiSandbox
Katalog'a eklenme: 2026-07-16
CISA'nın Zorunlu Kıldığı Aksiyon
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
CVSSv3 Score: 7.3 An improper certificate validation vulnerability in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backend destination website. Revised on 2026-09-08 00:00:00
CVSSv3 Score: 4.7 An improper access control vulnerability in FortiManager may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests. Revised on 2026-09-08 00:00:00