← Back to Feed

Fortinet FortiSandbox OS Command Injection Vulnerability

CVE-2026-25089

July 31, 2026 · CISA · Severity: CRITICAL

Fortinet’s FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS products are affected by a critical OS command injection vulnerability, identified as CVE-2026-25089. This flaw enables unauthenticated attackers to execute arbitrary commands on the system by sending specially crafted HTTP requests. The vulnerability has been actively exploited in the wild, as noted in CISA’s Known Exploited Vulnerabilities catalog, highlighting its severity and immediate risk to users. Organizations using FortiSandbox solutions are at risk of unauthorized access and potential compromise of their systems. The exploitation of this vulnerability could lead to data breaches, system disruptions, or further network infiltration. Fortinet has yet to release a patch or mitigation guidance as of July 16, 2026, leaving affected users vulnerable until a fix is provided. This issue underscores the importance of promptly addressing known vulnerabilities and monitoring for updates from vendors to safeguard critical infrastructure.

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Vendor: Fortinet Product: FortiSandbox CISA Date Added: 2026-07-16 CVE: CVE-2026-25089 This vulnerability is actively exploited in the wild according to CISA Known Exploited Vulnerabilities catalog.

Key Takeaways

  • CVE-2026-25089 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
  • The vulnerability allows SQL injection attacks, which can lead to data theft, authentication bypass, or remote code execution.
  • CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
  • Fortinet FortiSandbox: Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
☕ Buy a Coffee