ALITEQ.

a 9.8 in Fortinet's FortiSandbox lets anyone run commands with one crafted request and it's being exploited

CVE-2026-25089 is an unauthenticated command-injection flaw in FortiSandbox, the security appliance meant to catch malware. It's on CISA's exploited list. The tool that inspects threats has become one.

Priya NairUpdated 2d ago9 min read
NVD detail for CVE-2026-25089 showing a 9.8 FortiSandbox command injection

There's a grim irony in CVE-2026-25089: FortiSandbox is the security appliance whose whole job is to detonate and detect malware in isolation — and this flaw turns it into the attacker's entry point. It's a 9.8 OS command injection that lets an unauthenticated attacker run commands on the appliance via a specially crafted HTTP request — no login required. It's on CISA's Known Exploited Vulnerabilities catalog with active exploitation confirmed. If you run FortiSandbox, the tool meant to protect you is the one that now needs protecting, and patching it is urgent.

0.0/ 10

CVSS severity: Critical

Unauthenticated OS command injection via crafted HTTP — actively exploited, on CISA KEV.

Why a security appliance is a prize target

Security appliances like FortiSandbox are exactly what attackers love to compromise, for the same reasons as Ivanti Sentry and Fortinet's other edge products: they're network-connected by design, they run with high privilege, they're trusted deeply inside the environment, and their code often handles untrusted input in complex ways. Owning the box that inspects your threats gives an attacker a trusted foothold in the heart of your security stack — and a place to hide. That an unauthenticated command injection here is already being exploited is entirely predictable, and it's why this class of bug demands the fastest possible patching.

Network security appliance and cabling
FortiSandbox is meant to catch malware — an unauthenticated flaw turns the inspector into the intruder's foothold. · Unsplash

What to do

Update FortiSandbox to a patched release immediately — check your version against the affected 5.0/4.4/4.2 ranges.

Restrict access to the FortiSandbox web UI — it should not be reachable from untrusted networks.

Because it's exploited and pre-auth, hunt for compromise: unexpected processes, config changes, outbound connections.

If FortiSandbox Cloud/PaaS, confirm your instance is on a patched build and review access logs.

Quick answers

Is CVE-2026-25089 being exploited?
Yes — it's on CISA's Known Exploited Vulnerabilities catalog with active exploitation confirmed. Combined with its profile (unauthenticated, network-based command injection via HTTP), that makes it a top-priority patch. Attackers scan for exposed, unpatched security appliances precisely because they offer a trusted foothold. If your FortiSandbox is internet-reachable and unpatched, treat it as at high risk of compromise and patch immediately, then hunt for signs of intrusion.
Which FortiSandbox versions are affected?
FortiSandbox 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, all 4.2 versions, and FortiSandbox Cloud and PaaS 5.0.4–5.0.5. Check your exact version against these ranges and update to a patched release. If you're on the affected 4.2 branch (all versions), that's a clear signal to upgrade. The Cloud and PaaS variants need confirmation that your instance is on a fixed build.
What should I do after patching FortiSandbox?
Because the flaw is unauthenticated and actively exploited, assume a long-unpatched, exposed appliance may already be compromised. After patching, hunt for signs of intrusion — unexpected processes, modified configuration, unusual outbound connections — and rotate any credentials the appliance holds. Restrict the web UI to trusted networks going forward. Treating it as a potential incident, not just a patch, is the right posture for an exploited security-appliance bug.

When the appliance that inspects malware becomes the way in, urgency is the only sane response. Patch FortiSandbox now, restrict its web UI, and hunt if you were exposed. Sources: NVD and CISA KEV. It joins the month's edge-appliance criticals — Ivanti and CitrixBleed — where trusted security kit became the target.

Software & Systems Editor

Priya Nair

Priya has daily-driven more Linux distros than she can name and treats her setup like a workshop. She covers the operating systems, apps and settings worth your time — and cheerfully calls out the 'optimizations' that just quietly break your machine.

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading