Fortinet FortiSandbox Vulnerability Allows Attackers to Execute Unauthorized Commands
ID: 5d921c17-f544-5c5e-b52b-6b02628b78d6
STIX ID: report--5d921c17-f544-5c5e-b52b-6b02628b78d6
Feed Name: cybersecurityNews.com
Threat Score
Fortinet disclosed CVE-2026-25089, a critical (CVSSv3 9.1) unauthenticated OS command injection in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS web interfaces that can allow remote attackers to execute arbitrary OS commands; affected versions are listed (upgrade to 5.0.6 or 4.4.9 or above) and immediate actions include patching, restricting web UI access, and monitoring logs—no active exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
