CVE-2026-25089 CRITICAL

Fortinet FortiSandbox Vulnerability
Generated: 10 Oct 2026 19:57 • CVE Threat Intelligence

Description

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

9.8
CVSS CRITICAL

Details

Published
16 Jul 2026 00:00
Modified
N/A
Source
CIRCL
Vendor
Fortinet
Product
FortiSandbox
Fix Version
Vendor Patch / Mitigation Available

References