Vulnerabilities · 84 days ago

Unauthenticated HTTP can seize FortiSandbox management

An exposed FortiSandbox management interface is enough to hand over the box. The flaw lets an unauthenticated HTTP request cross the trust boundary and become OS command execution, so this is full compromise of the sandbox, not a narrow admin bug.

INCIBE ties CVE-2026-25089 to improper neutralization of special elements in FortiSandbox. A crafted HTTP request can be treated as shell input on FortiSandbox 5.0, 4.4, FortiSandbox Cloud 5.0, and FortiSandbox PaaS 5.0, with fixes in 5.0.6, 4.4.9, and 5.0.6 for the cloud and PaaS branches.

The practical risk is that the appliance can become the attacker’s foothold wherever it gates detonation or analysis workflows. If the management plane is reachable, treat it as high-risk until patched.

CVE-2026-25089

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: a improper neutralization of special elements used in an os command ('os command injection') vulnerability in… EPSS 76% (99th percentile).

CISA federal remediation date Jul 19

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Fortinet

Part of the PlainSec briefing for 2026-07-10

Editions

Related stories