peter bassill · operator
$ cve CVE-2026-25089 JSON

CVE-2026-25089 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 76.1% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2026-07-19.

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS76.11% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2026-07-19
Public exploitnone known
Published2026-06-09
Last modified2026-07-23

CISA KEV

NameFortinet FortiSandbox OS Command Injection Vulnerability
Added2026-07-16
Due2026-07-19
Vendor / productFortinet / FortiSandbox
Ransomware usenone reported

Affected (3)

VendorProduct
fortinetfortisandbox
fortinetfortisandbox cloud
fortinetfortisandbox paas

References

→ the Explorer  ·  watch your stack  ·  NVD