logo

Fortinet patched a new critical FortiSandbox flaw

ID: 5b9d9655-262f-55f7-b63b-95fcba723822

STIX ID: report--5b9d9655-262f-55f7-b63b-95fcba723822

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Pierluigi Paganini

...
...

Fortinet released security updates to fix a critical FortiSandbox OS command injection vulnerability (CVE-2026-25089, CVSS 9.8) that could allow unauthenticated attackers to execute arbitrary commands via crafted HTTP requests; affected FortiSandbox and FortiSandbox Cloud/PaaS versions are listed with upgrade guidance. The advisory also addresses two medium-severity flaws in FortiOS, FortiProxy, and FortiPortal, and the vendor reported no known active exploitation at the time of disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.