
Software
a 9.8 in Fortinet's FortiSandbox lets anyone run commands with one crafted request — and it's being exploited
CVE-2026-25089 is an unauthenticated command-injection flaw in FortiSandbox, the security appliance meant to catch malware. It's on CISA's exploited list. The tool that inspects threats has become one.
Priya Nair · 2d ago · 9 min