CVE-2026-25089
published 2026-06-09CVE-2026-25089: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-07-19
Exploited in the wild
EPSS
76.11%
99.5th percentile
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | 4.2.0 – 4.2.8 | — |
| fortinet | fortisandbox | 4.2.1 – 4.2.8 | — |
| fortinet | fortisandbox | >= 4.4.0 < 4.4.9 | 4.4.9 |
| fortinet | fortisandbox | 4.4.0 – 4.4.8 | — |
| fortinet | fortisandbox | >= 5.0.0 < 5.0.6 | 5.0.6 |
| fortinet | fortisandbox | 5.0.0 – 5.0.5 | — |
| fortinet | fortisandbox_cloud | >= 5.0.4 < 5.0.6 | 5.0.6 |
| fortinet | fortisandbox_cloud | 5.0.4 – 5.0.5 | — |
| fortinet | fortisandbox_paas | >= 5.0.4 < 5.0.6 | 5.0.6 |
| fortinet | fortisandbox_paas | 5.0.4 – 5.0.5 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target vector is specifically crafted HTTP requests to FortiSandbox WEB UI; monitor for anomalous/malformed HTTP requests to FortiSandbox management interfaces, particularly those targeting the 'start vnc' feature JSON input endpoint ↗
- →The vulnerability is a second-order OS command injection via JSON input on the 'start vnc' feature; inspect JSON payloads sent to the VNC-related API endpoint for OS command injection characters/sequences ↗
- →Active exploitation observed in the wild alongside CVE-2026-39813 and CVE-2026-39808; correlate FortiSandbox alerts across all three CVEs as threat actors are chaining them ↗
- →The exploit for CVE-2026-25089 shows signs of AI-generated tooling and is noted as faulty; no working public exploit has been disclosed, but exploitation attempts are still being observed — treat any exploitation attempt as potentially automated/AI-assisted ↗
- →CVE-2026-25089 is listed on CISA KEV with a remediation due date of 2026-07-19; CISA also requires forensic triage per BOD 26-04 for affected internet-exposed assets ↗
- ·Affected versions span multiple product lines: FortiSandbox 5.0.0–5.0.5, FortiSandbox 4.4.0–4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4–5.0.5, FortiSandbox PaaS 5.0.4–5.0.5; ensure detection/patching scope covers all three deployment types ↗
- ·CVSS score discrepancy between sources: NVD/THN report 9.1, while FortiGuard PSIRT reports 9.8 (Critical); use 9.8 for internal risk prioritization as it is the vendor's own assessment ↗
- ·The vulnerability is unauthenticated (no credentials required), making internet-exposed FortiSandbox WEB UI instances at highest risk; CISA BOD 26-04 guidance requires evaluating internet exposure of each asset ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox
ghsa_unreviewed·2026-06-09
CVE-2026-25089 [CRITICAL] CWE-78 A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
VulnCheck
Fortinet fortisandbox Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2026·CVSS 9.8
CVE-2026-25089 [CRITICAL] Fortinet fortisandbox Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Fortinet fortisandbox Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
Affected: Fortinet fortisandbox
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://x.com/DefusedCyber/status/2066575288503255274
CISA
Fortinet FortiSandbox OS Command Injection Vulnerability
cisa·2026-07-16·CVSS 9.8
CVE-2026-25089 [CRITICAL] CWE-78 Fortinet FortiSandbox OS Command Injection Vulnerability
Vulnerability: Fortinet FortiSandbox OS Command Injection Vulnerability
Affected: Fortinet FortiSandbox
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherenc
Fortinet
Second-Order OS Command Injection via JSON Input on start vnc feature
vendor_fortinet·2026-06-09·CVSS 9.8
CVE-2026-25089 [CRITICAL] CWE-78 Second-Order OS Command Injection via JSON Input on start vnc feature
FG-IR-26-141: Second-Order OS Command Injection via JSON Input on start vnc feature
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
CVEs: CVE-2026-25089
CWEs: CWE-78
CVSS: 9.8 (critical)
Affected products: FortiSandbox, Fortinet
No detection rules found.
No public exploits indexed.
Hackernews
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
blogs_hackernews·2026-07-17·CVSS 6.5
CVE-2026-58644 [MEDIUM] CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.
The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute arbitrary code.
"In a network-based attack, an attacker authenticated as at least a Sit
Checkpoint
22nd June – Threat Intelligence Report
blogs_checkpoint·2026-06-22
CVE-2026-42824 22nd June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 22nd June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident exposed driver’s license information, passport numbers, emails, phone numbers, and residential addresses for 3,087,721 hunting and fishing license customers. Social Security numbers and payment dat
Bleepingcomputer
Critical Fortinet FortiSandbox flaws now exploited in attacks
blogs_bleepingcomputer·2026-06-16·CVSS 6.5
CVE-2026-39813 [MEDIUM] Critical Fortinet FortiSandbox flaws now exploited in attacks
## Critical Fortinet FortiSandbox flaws now exploited in attacks
## Sergiu Gatlan
Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused.
Fortinet released security updates for these three critical-severity security flaws (tracked as CVE-2026-39813 , CVE-2026-39808 , and CVE-2026-25089 ) on April 14.
These flaws allow unauthenticated threat actors to escalate privileges and execute unauthorized code remotely through low-complexity command injection attacks that require no user interaction. To resolve these issues and block incoming attacks, admins must upgrade affected deployments to the latest released versions.
"We are observing exploitation of multiple Fortinet FortiS
Hackernews
Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
blogs_hackernews·2026-06-16·CVSS 9.8
CVE-2026-39813 [CRITICAL] Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber.
In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808 , and CVE-2026-25089 over the past 24 hours.
CVE-2026-39813 (CVSS score: 9.1) refers to a path traversal vulnerability in FortiSandbox JRPC API that could allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests.
The second flaw, CVE-2026-39808 (CVSS score: 9.1), is a case o
Hackernews
Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
blogs_hackernews·2026-06-10·CVSS 10.0
CVE-2026-25089 [CRITICAL] Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure.
The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI. It's tracked as CVE-2026-25089 (CVSS score: 9.1).
"An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allo
2026-06-09
Published
2026-07-16
Added to CISA KEV
Exploited in the wild