Article may be outdated

This article is 38 days old. Some details may have changed since publication.

Hacker News·4 min read·hard

CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV

S
slvnx
CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV
AI Summary

CISA has added a critical unauthenticated command injection vulnerability in Fortinet's FortiSandbox to its Known Exploited Vulnerabilities catalog. The flaw allows attackers to execute arbitrary commands via the web interface, posing a significant risk to enterprise networks.

Why it matters

Because FortiSandbox is a central component in many security stacks, this vulnerability could allow attackers to bypass automated threat responses.

Dive DeeperCreate a free account to unlock

Fortinet FortiSandbox contains an unauthenticated OS command injection vulnerability in its web interface. Fortinet's CNA record assigns CVSS 9.8, while its PSIRT advisory lists 9.1; NVD has not issued an independent score. Defused reported exploitation attempts in mid-June, and CISA added CVE-2026-25089 to KEV on July 16 with a July 19 deadline for applicable FCEB systems. This is the third FortiSandbox vulnerability exploited in the wild within two months.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness
Political Bias
Center
LeftLean LCenterLean RRight
Confidence: 95%

The report is a factual summary of a cybersecurity advisory and threat intelligence data.

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in