CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV

CISA has added a critical unauthenticated command injection vulnerability in Fortinet's FortiSandbox to its Known Exploited Vulnerabilities catalog. The flaw allows attackers to execute arbitrary commands via the web interface, posing a significant risk to enterprise networks.
Why it matters
Because FortiSandbox is a central component in many security stacks, this vulnerability could allow attackers to bypass automated threat responses.
Fortinet FortiSandbox contains an unauthenticated OS command injection vulnerability in its web interface. Fortinet's CNA record assigns CVSS 9.8, while its PSIRT advisory lists 9.1; NVD has not issued an independent score. Defused reported exploitation attempts in mid-June, and CISA added CVE-2026-25089 to KEV on July 16 with a July 19 deadline for applicable FCEB systems. This is the third FortiSandbox vulnerability exploited in the wild within two months.
CVE-2026-25089 (CWE-78: Improper Neutralization of Special Elements used in an OS Command) is an OS command injection in FortiSandbox's web UI. The flaw is reported to affect the "start VNC" feature — an attacker can inject shell metacharacters via JSON payloads in HTTP requests to this endpoint. No authentication is required, no user interaction is needed, and attack complexity is low.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in