Fortinet fixed a critical flaw in FortiSandbox that could let an attacker take over affected appliances over the internet without a password. The bug, CVE-2026-25089, is an OS command injection issue in the FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS web interface, exploitable via crafted HTTP requests for arbitrary command execution. Fixes shipped in FortiSandbox 5.0.6 and 4.4.9, FortiSandbox Cloud 5.0.6, and FortiSandbox PaaS 5.0.6; Fortinet also patched two medium-severity flaws in FortiOS, FortiProxy, and FortiPortal.
2026.07.17
97% relevant
This updates the same FortiSandbox event by adding that CISA has now placed CVE-2026-25089 in the KEV catalog as actively exploited, alongside a second FortiSandbox command-injection flaw, CVE-2026-39808, and notes Defused observed exploitation attempts.
Sergiu Gatlan
2026.07.17
94% relevant
This source advances the same underlying event by adding CISA confirmation that CVE-2026-25089 is being actively exploited, pairing it with CVE-2026-39808, and imposing a July 19 federal remediation deadline after both were added to the KEV catalog.
Eduard Kovacs
2026.06.17
92% relevant
This article updates that story with evidence of active exploitation of CVE-2026-25089 after disclosure, and adds that attackers are also targeting FortiSandbox CVE-2026-39808 and CVE-2026-39813 in the wild.
2026.06.16
96% relevant
This article updates the same underlying event by adding that CVE-2026-25089 is now being actively exploited and linking it with two other critical FortiSandbox flaws, CVE-2026-39813 and CVE-2026-39808, that Defused says are also under attack.
info@thehackernews.com (The Hacker News)
2026.06.16
95% relevant
This article updates the same FortiSandbox event by adding that attackers are exploiting three FortiSandbox flaws, including CVE-2026-25089, and broadens the picture from a single critical patched bug to an active exploitation cluster affecting the same product line.
Sergiu Gatlan
2026.06.16
96% relevant
This updates the same FortiSandbox vulnerability event by adding that CVE-2026-25089 is now being exploited in real attacks, alongside CVE-2026-39813 and CVE-2026-39808, after Fortinet's April patches.
Arctic Wolf Labs
2026.06.15
97% relevant
This source covers the same underlying Fortinet FortiSandbox event and adds defender-focused details on affected version ranges, the likely vulnerable 'start VNC' web UI path, cloud and PaaS scope, and recommended mitigations such as restricting web UI exposure and using WAF rules. It also notes that no active exploitation had been confirmed as of mid-June 2026.
Ionut Arghire
2026.06.10
100% relevant
The article establishes a distinct Fortinet patch event centered on CVE-2026-25089 in FortiSandbox, which is not the same underlying event as any existing tracked story.