logo

Critical Fortinet FortiSandbox Flaw Enables Remote Code Execution

ID: 5cfee32e-7164-50b5-b74f-072a872d63b8

STIX ID: report--5cfee32e-7164-50b5-b74f-072a872d63b8

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: AnuPriya

...
...

A critical missing-authorization vulnerability (CWE-862) in Fortinet FortiSandbox—impacting multiple on-premises, Cloud, and PaaS releases—allows unauthenticated attackers to craft HTTP requests that can execute arbitrary code or system commands on the appliance; Fortinet published fixed releases and administrators are urged to upgrade or migrate to patched versions immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.