CVE-2026-25089
CVE-2026-25089 is a critical command injection vulnerability in Fortinet FortiSandbox products, allowing unauthenticated attackers to execute arbitrary commands via crafted HTTP requests. CISA has marked it as known-exploited and requires immediate mitigation per vendor guidelines.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Fortinet FortiSandbox (versions 5.0.0-5.0.5, 4.4.0-4.4.8, 4.2.x), FortiSandbox Cloud (5.0.4-5.0.5), FortiSandbox PaaS (5.0.4-5.0.5)
Real-world impact
Known-exploited (CISA KEV: YES). Attackers can execute unauthorized commands, leading to potential system compromise.
Why this severity
CVSS 9.8 (critical): High confidence in remote code execution without authentication.
What to do about it
- 01Apply mitigations per Fortinet vendor instructions
- 02Follow CISA BOD 26-04 patching guidelines
- 03Discontinue use if mitigations are unavailable
- 04Prioritize patching based on internet exposure (CISA BOD 26-04)
- ›Restrict HTTP request input validation
- ›Monitor for suspicious command execution patterns
CISA KEV guidance and vendor advisories required for exact steps
Timeline
- Jun 9, 2026 · Jun 9, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 16, 2026 · 19d agoConfirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jul 19, 2026 · 16d agoCISA remediation deadlineFederal agencies are required to remediate by this date.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- fortiguard.fortinet.com/psirt/FG-IR-26-141vendor advisory
- cisa.gov/known-exploited-vulnerabili…us government resource