Security
Loading…

CVE-2026-25089

CRITICALCVSS 9.8Known Exploited
Description

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

Timeline
Published:June 9th, 2026 4:16 PM
Last modified:July 17th, 2026 5:16 AM
Added to KEV:July 16th, 2026
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

fortinet

Products

fortisandboxfortisandbox_cloudfortisandbox_paas
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute