CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands
ID: 90d9b8a8-2002-5410-b2ae-ae7db6d76894
STIX ID: report--90d9b8a8-2002-5410-b2ae-ae7db6d76894
Feed Name: GBHackers
**Executive summary:** CISA added two critical Fortinet FortiSandbox vulnerabilities (CVE-2026-39808 and CVE-2026-25089) to its Known Exploited Vulnerabilities catalog; both are unauthenticated OS command injection flaws being actively exploited in the wild and affecting FortiSandbox appliances as well as FortiSandbox Cloud and PaaS, potentially allowing full system compromise, tampering with malware analysis, and lateral movement — CISA mandates federal remediation by July 19, 2026 and urges immediate mitigations, exposure assessments, forensic triage, and monitoring for indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
