ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-25089

CRITICAL Export PDF

Fortinet FortiSandbox Vulnerability

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

CVSS Score
9.8
CRITICAL
Published
16 Jul 2026 00:00
Modified
N/A
Vendor
Fortinet
Product
FortiSandbox
Source
CIRCL

Affected Versions

Fix Vendor Patch / Mitigation Available

Weaknesses (CWE)

CWE-78

Affected Systems

Fortinet
FortiSandbox
Fortinet
FortiOS
FortiSandbox

KEV Status

Known Exploited Vulnerability