Fortinet patched a new critical FortiSandbox flaw
ID: 5b9d9655-262f-55f7-b63b-95fcba723822
STIX ID: report--5b9d9655-262f-55f7-b63b-95fcba723822
Feed Name: Security Affairs
Fortinet released security updates to fix a critical FortiSandbox OS command injection vulnerability (CVE-2026-25089, CVSS 9.8) that could allow unauthenticated attackers to execute arbitrary commands via crafted HTTP requests; affected FortiSandbox and FortiSandbox Cloud/PaaS versions are listed with upgrade guidance. The advisory also addresses two medium-severity flaws in FortiOS, FortiProxy, and FortiPortal, and the vendor reported no known active exploitation at the time of disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
