CVE-2026-25089
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a improper neutralization of special elements used in an os command ('os command injection') vulnerability in… EPSS 76% (99th percentile).
CISA federal remediation date Jul 19
Vulnerabilities · 84 days ago
An exposed FortiSandbox management interface is enough to hand over the box. The flaw lets an unauthenticated HTTP request cross the trust boundary and become OS command execution, so this is full compromise of the sandbox, not a narrow admin bug.
INCIBE ties CVE-2026-25089 to improper neutralization of special elements in FortiSandbox. A crafted HTTP request can be treated as shell input on FortiSandbox 5.0, 4.4, FortiSandbox Cloud 5.0, and FortiSandbox PaaS 5.0, with fixes in 5.0.6, 4.4.9, and 5.0.6 for the cloud and PaaS branches.
The practical risk is that the appliance can become the attacker’s foothold wherever it gates detonation or analysis workflows. If the management plane is reachable, treat it as high-risk until patched.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a improper neutralization of special elements used in an os command ('os command injection') vulnerability in… EPSS 76% (99th percentile).
CISA federal remediation date Jul 19
1 source covering this story
Neutralización incorrecta de elementos especiales en FortiSandbox de Fortinet
Adham El Karn, del equipo de seguridad de productos de Fortinet, ha reportado una vulnerabilidad de se
Part of the PlainSec briefing for 2026-07-10