CVE-2026-25089
Published Jun 9, 2026
Last updated 9 days ago
AI description
CVE-2026-25089 is an operating system (OS) command injection vulnerability affecting Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. This flaw, categorized as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), allows an unauthenticated, remote attacker to execute unauthorized commands on the appliance. The vulnerability is triggered by sending specially crafted HTTP requests, specifically exploiting a second-order command injection within the JSON input of the "start VNC" feature in the web-based management interface. Successful exploitation of CVE-2026-25089 can lead to the execution of arbitrary OS commands on the underlying system. Affected versions include FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, all FortiSandbox 4.2 versions, FortiSandbox Cloud 5.0.4 through 5.0.5, and FortiSandbox PaaS 5.0.4 through 5.0.5.
- Description
- A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
- Source
- psirt@fortinet.com
- NVD status
- Analyzed
- Products
- fortisandbox, fortisandbox_cloud, fortisandbox_paas
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Fortinet FortiSandbox OS Command Injection Vulnerability
- Exploit added on
- Jul 16, 2026
- Exploit action due
- Jul 19, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- psirt@fortinet.com
- CWE-78
- Hype score
- Not currently trending
US federal agencies faced a deadline today to patch Fortinet FortiSandbox after CISA confirmed active exploitation. CVE-2026-25089 lets an unauthenticated attacker run OS commands via a crafted HTTP request. Fortinet $FTNT shipped fixes June 9. Per BleepingComputer. https://t.co/
@ShortInfoNews
19 Jul 2026
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Today's #CTI brief for 2026-07-18: The dangerous systems are still being filed under "internal collaboration" and "security tooling," right up to the point they become a foothold. SharePoint CVE-2026-58644 and FortiSandbox CVE-2026-25089/CVE-2026-39808 have a July 19 federal
@alphahunt_io
18 Jul 2026
45 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
FortiSandbox has two unauthenticated command-injection RCEs — CVE-2026-25089 & CVE-2026-39808, CVSS 9.8. Both on CISA KEV, exploited in the wild, federal patch deadline Jul 19. The catch: it's the box your Fortinet fabric asks whether a file is malware. Runbook 🧵 https:
@zerohuntai
18 Jul 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Fortinet watch: BleepingComputer reports CISA ordered agencies to patch two actively exploited FortiSandbox flaws, CVE-2026-39808 and CVE-2026-25089, by Sunday, July 19. #Cybersecurity #KEV https://t.co/1aUYI3bY5G
@Divinmentis
18 Jul 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
2 Replies
0 Quotes
CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog on July 16, all with active exploitation evidence: two Fortinet FortiSandbox OS command injection flaws (CVE-2026-25089, CVE-2026-39808) and a Microsoft SharePoint deserialization RCE
@juliobmelo
18 Jul 2026
243 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
2 Fortinet FortiSandbox bugs are being exploited right now — if your company uses it, assume attackers can reach YOUR network unless it’s patched today. CISA just added CVE-2026-39808 + CVE-2026-25089 to KEV (CVSS 9.1) → patch/mitigate now. Read: https://t.co/Iy8QjXrNpa
@FaultSignal_
17 Jul 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Deux vulnérabilités critiques (CVE-2026-39808 et CVE-2026-25089) touchant FortiSandbox sont désormais exploitées dans des attaques. Leur inscription au catalogue KEV de la CISA confirme l’urgence de mettre à jour les systèmes concernés. https://t.co/EhrxZv8Ea8
@cert_ist
17 Jul 2026
190 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
1 Quote
CISA KEV lista duas falhas Fortinet FortiSandbox já exploradas: CVE-2026-39808 e CVE-2026-25089. Ambas envolvem execução de comandos por HTTP sem login. Priorize inventário, exposição à internet e mitigação do fornecedor. https://t.co/nzrhmIAKOk https://t.co/uvuI3HvuBa
@luizlcsec
17 Jul 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA adds actively exploited vulnerabilities to KEV: • CVE-2026-39808 & CVE-2026-25089 – Fortinet FortiSandbox (Critical) • CVE-2026-58644 – Microsoft SharePoint (CVSS 9.8) Federal agencies must patch by July 19. Prioritize these updates. #CISA #Vulnerability #Patc
@ThreatByte
17 Jul 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CISA KEV ALERT — Fortinet FortiSandbox 2-CVE Cluster CVE-2026-25089 (9.8) — OS Command Injection CVE-2026-39808 (9.8) — OS Command Injection Unauthenticated RCE via crafted HTTP requests. Active exploitation confirmed. → https://t.co/5fEKkKP5Ka #cybersecurity #Fo
@ThreatAft
17 Jul 2026
54 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA KEV catalog adds three actively exploited flaws: FortiSandbox CVE-2026-25089, CVE-2026-39808, and SharePoint CVE-2026-58644. Patch by July 19. #CISA #KEV #Fortinet #FortiSandbox #SharePoint #CVE202658644 #ActivelyExploited #CyberSecurity https://t.co/piHbyDae7Q
@Daily_CyberSec
17 Jul 2026
350 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
【常連】米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログにFortiSandboxのCVE-2026-25089及びCVE-2026-39808、並びにSharePointのCVE-2026-58644を追加。対処期限はいずれも3日語の7/19。
@__kokumoto
16 Jul 2026
756 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-25089: Unauthenticated OS command injection in Fortinet FortiSandbox (CVSS 9.8). Third FortiSandbox CVE exploited in 2026. CISA KEV listed today. How to find exposed instances: https://t.co/hb4AlwlIXj
@hellorecon
16 Jul 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
FortiSandbox has two command-injection CVEs in CISA KEV as of 2026-07-16: CVE-2026-39808 and CVE-2026-25089. The due date is 2026-07-19. But exploitation was reported in mid-June. That leaves roughly a month between confirmed in-the-wild activity and the formal signal many patch
@empherehq
16 Jul 2026
54 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🛡️We added Fortinet FortiSandbox vulnerabilities CVE-2026-25089 & CVE-2026-39808 and Microsoft SharePoint vulnerability CVE-2026-58644 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec
@CISACyber
16 Jul 2026
6150 Impressions
7 Retweets
29 Likes
3 Bookmarks
2 Replies
1 Quote
⚠️ استغلال فعلي لثلاث ثغرات حرجة في FortiSandbox تتيح تجاوز المصادقة وحقن أوامر نظام دون أي تدخل من المستخدم المعرّفات : CVE-2026-39813, CVE-2026-39808, CVE-2026-25089 درجة الخطور
@KasperskyDev
27 Jun 2026
88 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
FortiSandbox mit kritischer Sicherheitslücke https://t.co/hocJXctsHh Fortinet hat mit der Sicherheitsmeldung CVE-2026-25089 eine kritische Schwachstelle in FortiSandbox offengelegt, die laut NVD mit CVSS 9.8 bewertet wird. Über die Lücke kann ein nicht authentifizierter Angr
@B2bCyber
21 Jun 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
FortiSandbox: 3 CVEs exploited Three FortiSandbox flaws under active exploitation, all already patched: •CVE-2026-39813 (9.1) auth bypass •CVE-2026-39808 (9.1) OS command injection •CVE-2026-25089 (9.1) unauth command execution (Web UI) It feeds verdicts to your whole
@ElusivePrivacy
18 Jun 2026
64 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
【FortiSandboxの複数重大脆弱性に悪用試行】 Fortinet FortiSandboxで、CVE-2026-39813、CVE-2026-39808、CVE-2026-25089の悪用試行が報告されています。 認証バイパスやOSコマンドインジェクションにつながる脆弱性で、FortiSandb
@01ra66it
17 Jun 2026
254 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Intel Report [CRITICAL] - Three critical vulnerabilities in Fortinet FortiSandbox products (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089), each rated CVSS 9.1, are under active exploitation by unknown threat actors as of mid-June 2026. The... https://t.co/83LRIRhJvs
@EnigmaGlobalSW
17 Jun 2026
49 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Trois failles de FortiSandbox récemment corrigées sont actuellement exploitées. Les honeypots de Defused, entreprise de renseignement sur les exploits, ont détecté des tentatives d'exploitation des CVE-2026-39808, CVE-2026-39813, et CVE-2026-25089. https://t.co/rTfx9X359h
@cert_ist
17 Jun 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Upozorňujeme na aktivně zneužívané zranitelnosti ve Fortinet FortiSandbox, CVE-2026-39813, CVE-2026-39808, CVE-2026-25089. Útočníci aktivně zneužívají více chyb ve FortiSandbox, přičemž CVE-2026-39813 (CVSS 9.1) představuje path traversal v JRPC API umož
@GOVCERT_CZ
17 Jun 2026
540 Impressions
2 Retweets
5 Likes
1 Bookmark
0 Replies
0 Quotes
🚨 Fortinet FortiSandbox Alert Attackers are exploiting 3 critical flaws: 🔴 CVE-2026-39813 🔴 CVE-2026-39808 🔴 CVE-2026-25089 Patch now, restrict management access, and review logs. https://t.co/N121ehAPaM #CyberSecurity #Fortinet #CVE #Vulert
@vulert_official
17 Jun 2026
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Fortinet FortiSandboxの重大な脆弱性が攻撃に悪用される(CVE-2026-39813、CVE-2026-39808、CVE-2026-25089) | Codebook|Security News https://t.co/uEhZFFhodL
@ohhara_shiojiri
17 Jun 2026
49 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨Fortinet FortiSandboxの重大な脆弱性が攻撃に悪用される(CVE-2026-39813、CVE-2026-39808、CVE-2026-25089) ⚽️FIFA内部システムにバグ、W杯のテレビ配信を自由に改変できる状態に 〜サイバーアラート6月17日〜 https://t.c
@MachinaRecord
17 Jun 2026
200 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Fortinet reporta tres vulnerabilidades críticas en FortiSandbox explotadas activamente. CVE-2026-39813, CVE-2026-39808 y CVE-2026-25089 permiten ejecución remota de código. Parches disponibles, actualiza ya. https://t.co/cMe9dZVeH6
@TheVortiq
16 Jun 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are exploiting FortiSandbox vulnerabilities: Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat… https://t.co/55j3T5laWe h
@shah_sheikh
16 Jun 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔐 Exploit watch: The Hacker News reports active exploitation of Fortinet FortiSandbox flaws CVE-2026-39813, CVE-2026-39808 and CVE-2026-25089 over the past 24 hours, citing Defused Cyber. #Fortinet #Cybersecurity https://t.co/fiN9z90ZOl
@Divinmentis
16 Jun 2026
67 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Exploitation attempts detected against Fortinet #FortiSandbox targeting CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 (all CVSS 9.1). CVE-2026-39813 shows no prior #exploitation evidence, suggesting recent availability of working exploits. https://t.co/ZOvLG4wBNH
@MeridianEU
16 Jun 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE Alert: Fortinet FortiSandbox Attackers are reportedly exploiting three Fortinet FortiSandbox vulnerabilities: • CVE-2026-39813 | CVSS 9.1 • CVE-2026-39808 | CVSS 9.1 • CVE-2026-25089 | CVSS 9.1 The flaws include path traversal and OS command injection issues that cou
@CloneSystemsInc
16 Jun 2026
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cyber attackers are exploiting three critical vulnerabilities in Fortinet's FortiSandbox appliances: CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. These flaws allow unauthenticated access and command execution via crafted HTTP requests. Fortinet has released patches, but ht
@dailytechonx
16 Jun 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Active attacks target critical Fortinet FortiSandbox flaws, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, enabling privilege escalation and RCE without user interaction. #Fortinet #FortiSandbox #CVE2026 https://t.co/mYbEyw8GhX
@TweetThreatNews
16 Jun 2026
136 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨We are observing exploitation of multiple Fortinet FortiSandbox vulnerabilities during the past 24 hours, including: CVE-2026-39813 (no previous recorded exploitation) CVE-2026-39808 CVE-2026-25089 (vibecoded, likely faulty exploit) Per our research a working exploit for
@DefusedCyber
15 Jun 2026
5401 Impressions
15 Retweets
51 Likes
16 Bookmarks
2 Replies
1 Quote
🔒 #CyberSecurity CVE-2026-25089: FortiSandbox Command Injection — Detection and Remediation Guide "Fortinet addresses CVE-2026-25089 (CVSS 9.1), a critical command injection…" 🔗 https://t.co/69695owlOS #CyberSecurity #ThreatIntel #sigmarule #kqldetection #threathunt
@SecurityAr58409
11 Jun 2026
58 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "814D77BE-F536-42DE-B068-F92B95D68248",
"versionEndIncluding": "4.2.8",
"versionStartIncluding": "4.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "0025C9C0-8D61-4563-96F9-F4E09DD83B26",
"versionEndExcluding": "4.4.9",
"versionStartIncluding": "4.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3AAEF316-2134-4398-911C-E7532CD3AFF2",
"versionEndExcluding": "5.0.6",
"versionStartIncluding": "5.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox_cloud:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D479507F-4DD8-4455-A8DB-138AD56C6822",
"versionEndExcluding": "5.0.6",
"versionStartIncluding": "5.0.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox_paas:*:*:*:*:*:*:*:*",
"matchCriteriaId": "61A9A2E9-3086-4172-B3A3-212873B8C4A9",
"versionEndExcluding": "5.0.6",
"versionStartIncluding": "5.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]