a 9.8 in Fortinet's FortiSandbox lets anyone run commands with one crafted request — and it's being exploited

CVE-2026-25089 is an unauthenticated command-injection flaw in FortiSandbox, the security appliance meant to catch malware. It's on CISA's exploited…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

The flaw: OS command injection in FortiSandbox → unauthenticated remote command execution via crafted HTTP requests.

What you need to know

Affected: FortiSandbox 5.0.0–5.0.5, 4.4.0–4.4.8, all of 4.2, plus FortiSandbox Cloud and PaaS 5.0.4–5.0.5.

What you need to know

Actively exploited and on CISA's KEV catalog — this is confirmed in the wild.

What you need to know

Attack profile: network, no auth, no user interaction — the wormable/mass-scan class.

What you need to know

Fix: update FortiSandbox to a patched release now, and restrict the web UI's exposure.

Aliteq

Read the full story

a 9.8 in Fortinet's FortiSandbox lets anyone run commands with one crafted request — and it's being exploited

Read the full story on Aliteq