Skip to content
COOEY

EXPOSURES › CVE-2026-25089

CVE-2026-25089

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-07-16 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-25089 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Fortinet FortiSandbox OS Command Injection Vulnerability actively exploited before July 19, 2026

Fortinet's FortiSandbox is vulnerable to command injection attacks via HTTP, allowing unauthenticated attackers to execute arbitrary commands.

Shame score — Active exploitation indicates negligence in addressing a critical security flaw.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.