logo

Fortinet FortiSandbox Vulnerability Allows Attackers to Execute Unauthorized Commands

ID: 5d921c17-f544-5c5e-b52b-6b02628b78d6

STIX ID: report--5d921c17-f544-5c5e-b52b-6b02628b78d6

Feed Name: cybersecurityNews.com

Threat Score
82/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Guru Baran

...
...

Fortinet disclosed CVE-2026-25089, a critical (CVSSv3 9.1) unauthenticated OS command injection in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS web interfaces that can allow remote attackers to execute arbitrary OS commands; affected versions are listed (upgrade to 5.0.6 or 4.4.9 or above) and immediate actions include patching, restricting web UI access, and monitoring logs—no active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.