CVE-2026-25089 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 76.1% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2026-07-19.
Description
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 76.11% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | yes — remediate by 2026-07-19 |
| Public exploit | none known |
| Published | 2026-06-09 |
| Last modified | 2026-07-23 |
CISA KEV
| Name | Fortinet FortiSandbox OS Command Injection Vulnerability |
|---|---|
| Added | 2026-07-16 |
| Due | 2026-07-19 |
| Vendor / product | Fortinet / FortiSandbox |
| Ransomware use | none reported |
Affected (3)
| Vendor | Product |
|---|---|
| fortinet | fortisandbox |
| fortinet | fortisandbox cloud |
| fortinet | fortisandbox paas |
References
→ the Explorer · watch your stack · NVD