Fortinet patches critical FortiSandbox bug CVE-2026-25089 that lets attackers run code without logging in

Fortinet fixed a critical flaw in FortiSandbox that could let an attacker take over affected appliances over the internet without a password. The bug, CVE-2026-25089, is an OS command injection issue in the FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS web interface, exploitable via crafted HTTP requests for arbitrary command execution. Fixes shipped in FortiSandbox 5.0.6 and 4.4.9, FortiSandbox Cloud 5.0.6, and FortiSandbox PaaS 5.0.6; Fortinet also patched two medium-severity flaws in FortiOS, FortiProxy, and FortiPortal.
Why it matters: Organizations using FortiSandbox should update quickly because this is the kind of bug that can allow full remote compromise of a security appliance. Even though Fortinet says it has no evidence of attacks yet, internet-facing management interfaces are high-risk and should be patched or tightly restricted immediately.

Sources

Attackers target critical FortiSandbox flaws as CISA issues patch order
2026.07.17 97% relevant
This updates the same FortiSandbox event by adding that CISA has now placed CVE-2026-25089 in the KEV catalog as actively exploited, alongside a second FortiSandbox command-injection flaw, CVE-2026-39808, and notes Defused observed exploitation attempts.
CISA urges immediate action on actively exploited Fortinet flaws
Sergiu Gatlan 2026.07.17 94% relevant
This source advances the same underlying event by adding CISA confirmation that CVE-2026-25089 is being actively exploited, pairing it with CVE-2026-39808, and imposing a July 19 federal remediation deadline after both were added to the KEV catalog.
3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs
Eduard Kovacs 2026.06.17 92% relevant
This article updates that story with evidence of active exploitation of CVE-2026-25089 after disclosure, and adds that attackers are also targeting FortiSandbox CVE-2026-39808 and CVE-2026-39813 in the wild.
Three critical Fortinet sandbox bugs splattered by unknown attackers
2026.06.16 96% relevant
This article updates the same underlying event by adding that CVE-2026-25089 is now being actively exploited and linking it with two other critical FortiSandbox flaws, CVE-2026-39813 and CVE-2026-39808, that Defused says are also under attack.
Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
info@thehackernews.com (The Hacker News) 2026.06.16 95% relevant
This article updates the same FortiSandbox event by adding that attackers are exploiting three FortiSandbox flaws, including CVE-2026-25089, and broadens the picture from a single critical patched bug to an active exploitation cluster affecting the same product line.
Critical Fortinet FortiSandbox flaws now exploited in attacks
Sergiu Gatlan 2026.06.16 96% relevant
This updates the same FortiSandbox vulnerability event by adding that CVE-2026-25089 is now being exploited in real attacks, alongside CVE-2026-39813 and CVE-2026-39808, after Fortinet's April patches.
CVE-2026-25089: Fortinet FortiSandbox Critical OS Command Injection Vulnerability Immediate Action Required
Arctic Wolf Labs 2026.06.15 97% relevant
This source covers the same underlying Fortinet FortiSandbox event and adds defender-focused details on affected version ranges, the likely vulnerable 'start VNC' web UI path, cloud and PaaS scope, and recommended mitigations such as restricting web UI exposure and using WAF rules. It also notes that no active exploitation had been confirmed as of mid-June 2026.
Critical Vulnerabilities Patched in Fortinet, Ivanti Products
Ionut Arghire 2026.06.10 100% relevant
The article establishes a distinct Fortinet patch event centered on CVE-2026-25089 in FortiSandbox, which is not the same underlying event as any existing tracked story.
← Back to all stories