logo

Critical FortiSandbox Flaw Requires Immediate Patching

ID: bdeace8e-9899-57e5-8c07-7b7e03223fb6

STIX ID: report--bdeace8e-9899-57e5-8c07-7b7e03223fb6

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Do Son

...
...

### Executive Summary A critical unauthenticated command-injection vulnerability (CVE-2026-25089, CVSS 9.1) in Fortinet FortiSandbox's web UI allows attackers to execute OS commands via specially crafted HTTP/JSON requests (start VNC feature), impacting FortiSandbox appliances, Cloud, and PaaS; Fortinet has published patches (e.g., upgrade to 5.0.6 or 4.4.9) and administrators should urgently verify versions, apply updates, and monitor for suspicious HTTP traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.