CVE-2026-25089

Published Jun 9, 2026

Last updated 9 days ago

Exploit knownCVSS critical 9.8
Zero-day
Fortinet FortiSandbox
FortiSandbox Cloud
FortiSandbox PaaS

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-25089 is an operating system (OS) command injection vulnerability affecting Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. This flaw, categorized as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), allows an unauthenticated, remote attacker to execute unauthorized commands on the appliance. The vulnerability is triggered by sending specially crafted HTTP requests, specifically exploiting a second-order command injection within the JSON input of the "start VNC" feature in the web-based management interface. Successful exploitation of CVE-2026-25089 can lead to the execution of arbitrary OS commands on the underlying system. Affected versions include FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, all FortiSandbox 4.2 versions, FortiSandbox Cloud 5.0.4 through 5.0.5, and FortiSandbox PaaS 5.0.4 through 5.0.5.

Description
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
Source
psirt@fortinet.com
NVD status
Analyzed
Products
fortisandbox, fortisandbox_cloud, fortisandbox_paas

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Fortinet FortiSandbox OS Command Injection Vulnerability
Exploit added on
Jul 16, 2026
Exploit action due
Jul 19, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

psirt@fortinet.com
CWE-78

Social media

Hype score
Not currently trending
  1. US federal agencies faced a deadline today to patch Fortinet FortiSandbox after CISA confirmed active exploitation. CVE-2026-25089 lets an unauthenticated attacker run OS commands via a crafted HTTP request. Fortinet $FTNT shipped fixes June 9. Per BleepingComputer. https://t.co/

    @ShortInfoNews

    19 Jul 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Today's #CTI brief for 2026-07-18: The dangerous systems are still being filed under "internal collaboration" and "security tooling," right up to the point they become a foothold. SharePoint CVE-2026-58644 and FortiSandbox CVE-2026-25089/CVE-2026-39808 have a July 19 federal

    @alphahunt_io

    18 Jul 2026

    45 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. FortiSandbox has two unauthenticated command-injection RCEs — CVE-2026-25089 & CVE-2026-39808, CVSS 9.8. Both on CISA KEV, exploited in the wild, federal patch deadline Jul 19. The catch: it's the box your Fortinet fabric asks whether a file is malware. Runbook 🧵 https:

    @zerohuntai

    18 Jul 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. 🚨 Fortinet watch: BleepingComputer reports CISA ordered agencies to patch two actively exploited FortiSandbox flaws, CVE-2026-39808 and CVE-2026-25089, by Sunday, July 19. #Cybersecurity #KEV https://t.co/1aUYI3bY5G

    @Divinmentis

    18 Jul 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  5. CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog on July 16, all with active exploitation evidence: two Fortinet FortiSandbox OS command injection flaws (CVE-2026-25089, CVE-2026-39808) and a Microsoft SharePoint deserialization RCE

    @juliobmelo

    18 Jul 2026

    243 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. 2 Fortinet FortiSandbox bugs are being exploited right now — if your company uses it, assume attackers can reach YOUR network unless it’s patched today. CISA just added CVE-2026-39808 + CVE-2026-25089 to KEV (CVSS 9.1) → patch/mitigate now. Read: https://t.co/Iy8QjXrNpa

    @FaultSignal_

    17 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Deux vulnérabilités critiques (CVE-2026-39808 et CVE-2026-25089) touchant FortiSandbox sont désormais exploitées dans des attaques. Leur inscription au catalogue KEV de la CISA confirme l’urgence de mettre à jour les systèmes concernés. https://t.co/EhrxZv8Ea8

    @cert_ist

    17 Jul 2026

    190 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  8. CISA KEV lista duas falhas Fortinet FortiSandbox já exploradas: CVE-2026-39808 e CVE-2026-25089. Ambas envolvem execução de comandos por HTTP sem login. Priorize inventário, exposição à internet e mitigação do fornecedor. https://t.co/nzrhmIAKOk https://t.co/uvuI3HvuBa

    @luizlcsec

    17 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CISA adds actively exploited vulnerabilities to KEV: • CVE-2026-39808 & CVE-2026-25089 – Fortinet FortiSandbox (Critical) • CVE-2026-58644 – Microsoft SharePoint (CVSS 9.8) Federal agencies must patch by July 19. Prioritize these updates. #CISA #Vulnerability #Patc

    @ThreatByte

    17 Jul 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 CISA KEV ALERT — Fortinet FortiSandbox 2-CVE Cluster CVE-2026-25089 (9.8) — OS Command Injection CVE-2026-39808 (9.8) — OS Command Injection Unauthenticated RCE via crafted HTTP requests. Active exploitation confirmed. → https://t.co/5fEKkKP5Ka #cybersecurity #Fo

    @ThreatAft

    17 Jul 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CISA KEV catalog adds three actively exploited flaws: FortiSandbox CVE-2026-25089, CVE-2026-39808, and SharePoint CVE-2026-58644. Patch by July 19. #CISA #KEV #Fortinet #FortiSandbox #SharePoint #CVE202658644 #ActivelyExploited #CyberSecurity https://t.co/piHbyDae7Q

    @Daily_CyberSec

    17 Jul 2026

    350 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. 【常連】米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログにFortiSandboxのCVE-2026-25089及びCVE-2026-39808、並びにSharePointのCVE-2026-58644を追加。対処期限はいずれも3日語の7/19。

    @__kokumoto

    16 Jul 2026

    756 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  13. CVE-2026-25089: Unauthenticated OS command injection in Fortinet FortiSandbox (CVSS 9.8). Third FortiSandbox CVE exploited in 2026. CISA KEV listed today. How to find exposed instances: https://t.co/hb4AlwlIXj

    @hellorecon

    16 Jul 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. FortiSandbox has two command-injection CVEs in CISA KEV as of 2026-07-16: CVE-2026-39808 and CVE-2026-25089. The due date is 2026-07-19. But exploitation was reported in mid-June. That leaves roughly a month between confirmed in-the-wild activity and the formal signal many patch

    @empherehq

    16 Jul 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  15. 🛡️We added Fortinet FortiSandbox vulnerabilities CVE-2026-25089 & CVE-2026-39808 and Microsoft SharePoint vulnerability CVE-2026-58644 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec

    @CISACyber

    16 Jul 2026

    6150 Impressions

    7 Retweets

    29 Likes

    3 Bookmarks

    2 Replies

    1 Quote

  16. ⚠️ استغلال فعلي لثلاث ثغرات حرجة في FortiSandbox تتيح تجاوز المصادقة وحقن أوامر نظام دون أي تدخل من المستخدم المعرّفات : CVE-2026-39813, CVE-2026-39808, CVE-2026-25089 درجة الخطور

    @KasperskyDev

    27 Jun 2026

    88 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. FortiSandbox mit kritischer Sicherheitslücke https://t.co/hocJXctsHh Fortinet hat mit der Sicherheitsmeldung CVE-2026-25089 eine kritische Schwachstelle in FortiSandbox offengelegt, die laut NVD mit CVSS 9.8 bewertet wird. Über die Lücke kann ein nicht authentifizierter Angr

    @B2bCyber

    21 Jun 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. FortiSandbox: 3 CVEs exploited Three FortiSandbox flaws under active exploitation, all already patched: •CVE-2026-39813 (9.1) auth bypass •CVE-2026-39808 (9.1) OS command injection •CVE-2026-25089 (9.1) unauth command execution (Web UI) It feeds verdicts to your whole

    @ElusivePrivacy

    18 Jun 2026

    64 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 【FortiSandboxの複数重大脆弱性に悪用試行】 Fortinet FortiSandboxで、CVE-2026-39813、CVE-2026-39808、CVE-2026-25089の悪用試行が報告されています。 認証バイパスやOSコマンドインジェクションにつながる脆弱性で、FortiSandb

    @01ra66it

    17 Jun 2026

    254 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Intel Report [CRITICAL] - Three critical vulnerabilities in Fortinet FortiSandbox products (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089), each rated CVSS 9.1, are under active exploitation by unknown threat actors as of mid-June 2026. The... https://t.co/83LRIRhJvs

    @EnigmaGlobalSW

    17 Jun 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Trois failles de FortiSandbox récemment corrigées sont actuellement exploitées. Les honeypots de Defused, entreprise de renseignement sur les exploits, ont détecté des tentatives d'exploitation des CVE-2026-39808, CVE-2026-39813, et CVE-2026-25089. https://t.co/rTfx9X359h

    @cert_ist

    17 Jun 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🚨 Upozorňujeme na aktivně zneužívané zranitelnosti ve Fortinet FortiSandbox, CVE-2026-39813, CVE-2026-39808, CVE-2026-25089. Útočníci aktivně zneužívají více chyb ve FortiSandbox, přičemž CVE-2026-39813 (CVSS 9.1) představuje path traversal v JRPC API umož

    @GOVCERT_CZ

    17 Jun 2026

    540 Impressions

    2 Retweets

    5 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  23. 🚨 Fortinet FortiSandbox Alert Attackers are exploiting 3 critical flaws: 🔴 CVE-2026-39813 🔴 CVE-2026-39808 🔴 CVE-2026-25089 Patch now, restrict management access, and review logs. https://t.co/N121ehAPaM #CyberSecurity #Fortinet #CVE #Vulert

    @vulert_official

    17 Jun 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Fortinet FortiSandboxの重大な脆弱性が攻撃に悪用される(CVE-2026-39813、CVE-2026-39808、CVE-2026-25089) | Codebook|Security News https://t.co/uEhZFFhodL

    @ohhara_shiojiri

    17 Jun 2026

    49 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨Fortinet FortiSandboxの重大な脆弱性が攻撃に悪用される(CVE-2026-39813、CVE-2026-39808、CVE-2026-25089) ⚽️FIFA内部システムにバグ、W杯のテレビ配信を自由に改変できる状態に 〜サイバーアラート6月17日〜 https://t.c

    @MachinaRecord

    17 Jun 2026

    200 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Fortinet reporta tres vulnerabilidades críticas en FortiSandbox explotadas activamente. CVE-2026-39813, CVE-2026-39808 y CVE-2026-25089 permiten ejecución remota de código. Parches disponibles, actualiza ya. https://t.co/cMe9dZVeH6

    @TheVortiq

    16 Jun 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. Attackers are exploiting FortiSandbox vulnerabilities: Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat… https://t.co/55j3T5laWe h

    @shah_sheikh

    16 Jun 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 🔐 Exploit watch: The Hacker News reports active exploitation of Fortinet FortiSandbox flaws CVE-2026-39813, CVE-2026-39808 and CVE-2026-25089 over the past 24 hours, citing Defused Cyber. #Fortinet #Cybersecurity https://t.co/fiN9z90ZOl

    @Divinmentis

    16 Jun 2026

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  29. Exploitation attempts detected against Fortinet #FortiSandbox targeting CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 (all CVSS 9.1). CVE-2026-39813 shows no prior #exploitation evidence, suggesting recent availability of working exploits. https://t.co/ZOvLG4wBNH

    @MeridianEU

    16 Jun 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. CVE Alert: Fortinet FortiSandbox Attackers are reportedly exploiting three Fortinet FortiSandbox vulnerabilities: • CVE-2026-39813 | CVSS 9.1 • CVE-2026-39808 | CVSS 9.1 • CVE-2026-25089 | CVSS 9.1 The flaws include path traversal and OS command injection issues that cou

    @CloneSystemsInc

    16 Jun 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. Cyber attackers are exploiting three critical vulnerabilities in Fortinet's FortiSandbox appliances: CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. These flaws allow unauthenticated access and command execution via crafted HTTP requests. Fortinet has released patches, but ht

    @dailytechonx

    16 Jun 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. Active attacks target critical Fortinet FortiSandbox flaws, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, enabling privilege escalation and RCE without user interaction. #Fortinet #FortiSandbox #CVE2026 https://t.co/mYbEyw8GhX

    @TweetThreatNews

    16 Jun 2026

    136 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  33. 🚨We are observing exploitation of multiple Fortinet FortiSandbox vulnerabilities during the past 24 hours, including: CVE-2026-39813 (no previous recorded exploitation) CVE-2026-39808 CVE-2026-25089 (vibecoded, likely faulty exploit) Per our research a working exploit for

    @DefusedCyber

    15 Jun 2026

    5401 Impressions

    15 Retweets

    51 Likes

    16 Bookmarks

    2 Replies

    1 Quote

  34. 🔒 #CyberSecurity CVE-2026-25089: FortiSandbox Command Injection — Detection and Remediation Guide "Fortinet addresses CVE-2026-25089 (CVSS 9.1), a critical command injection…" 🔗 https://t.co/69695owlOS #CyberSecurity #ThreatIntel #sigmarule #kqldetection #threathunt

    @SecurityAr58409

    11 Jun 2026

    58 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations