Critical FortiSandbox Flaw Requires Immediate Patching
ID: bdeace8e-9899-57e5-8c07-7b7e03223fb6
STIX ID: report--bdeace8e-9899-57e5-8c07-7b7e03223fb6
Feed Name: securityonline.info
Threat Score
### Executive Summary A critical unauthenticated command-injection vulnerability (CVE-2026-25089, CVSS 9.1) in Fortinet FortiSandbox's web UI allows attackers to execute OS commands via specially crafted HTTP/JSON requests (start VNC feature), impacting FortiSandbox appliances, Cloud, and PaaS; Fortinet has published patches (e.g., upgrade to 5.0.6 or 4.4.9) and administrators should urgently verify versions, apply updates, and monitor for suspicious HTTP traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
