s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-25089

📛 CVE Title

CVE-2026-25089

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

Overview

State
PUBLISHED
Assigner (CNA)
fortinet
CVSS severity
CRITICAL
CVSS score
CVSS 9.1 / 10 9.1 9.1 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
Effective score
9.1 / 10 CRITICAL source: CNA overview
CWE(s)
CWE-78
Reserved
2026-01-29
Published
2026-06-09 14:27 UTC
Last updated
2026-06-10 13:35 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/25xxx/CVE-2026-25089.json
Linked Threat
CVE-2026-25089 — Fortinet FortiSandbox: Fortinet FortiSandbox OS Command Injection Vulnerability

CISA Known Exploited Vulnerabilities CISA KEV

CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.

Vulnerability name
Fortinet FortiSandbox OS Command Injection Vulnerability
Vendor / project
Fortinet
Product
FortiSandbox
Date added to KEV
2026-07-16
Remediation due
2026-07-19
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Ransomware campaign use
Unknown
CISA notes
https://fortiguard.fortinet.com/psirt/FG-IR-26-141 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-25089
CISA listing
www.cisa.gov/known-exploited-vulnerabilities-catalog

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-06-09 16:16:39 UTC
NVD last modified
2026-07-23 08:10:00 UTC
NVD CVSS v3.1
CVSS 9.8 / 10 9.8 9.8 / 10 CRITICAL source: psirt@fortinet.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability subscore
3.9 / 10
Impact subscore
5.9 / 10
EPSS score
0.6983 (probability of exploitation in next 30 days)
EPSS percentile
99.30% vs all CVEs — higher = more likely to be exploited, as of 2026-07-27

NVD / KEV / EPSS data refreshed 2026-07-27 19:19 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-35443
Assigner
fortinet
Published
Jun 9, 2026, 2:27:47 PM
Updated
Jul 17, 2026, 3:56:23 AM
EUVD base score (CVSS 3.1)
9.1 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
EUVD-reported EPSS
69.8300
Vendors
Fortinet
Products
FortiSandbox (4.2.1 ≤4.2.8)
FortiSandbox (5.0.0 ≤5.0.5)
FortiSandbox Cloud (5.0.4 ≤5.0.5)
FortiSandbox PaaS (5.0.4 ≤5.0.5)
FortiSandbox (4.4.0 ≤4.4.8)
Aliases
GHSA-gw24-hwf5-92h2

ENISA description: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

EUVD references (1)

Affected products (3)

VendorProductVersionsPlatforms
Fortinet FortiSandbox 5.0.0 (affected), 4.4.0 (affected), 4.2.1 (affected)
Fortinet FortiSandbox Cloud 5.0.4 (affected)
Fortinet FortiSandbox PaaS 5.0.4 (affected)

Affected products — CPE 2.3 (3) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*
  • cpe:2.3:a:fortinet:fortisandbox_cloud:*:*:*:*:*:*:*:*
  • cpe:2.3:a:fortinet:fortisandbox_paas:*:*:*:*:*:*:*:*

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

MITRE references (1) cveawg.mitre.org

Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

NVD-tagged references (2)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (2)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
cwe CWE-78 no local data 2026-07-17 05:32 UTC
cve CVE-2026-25089 no local data 2026-07-17 05:32 UTC

Flagged vendors

    Remediations (11)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • CISA KEV

      Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due date: 2026-07-19 Known ransomware campaign use: Unknown

      2026-07-17 05:32 UTC
    • web:howtofix.guide

      Attackers are probing Fortinet FortiSandbox CVE-2026-25089 , CVE - 2026 -39813, and CVE - 2026 -39808. Patch affected systems and check logs.

      2026-06-19 02:12 UTC
    • web:nvd.nist.gov

      Official websites use .gov A .gov website belongs to an official government organization in the United States.

      2026-06-19 02:12 UTC
    • web:securityaffairs.com

      Fortinet patched a critical FortiSandbox vulnerability that could let unauthenticated attackers remotely execute commands via crafted HTTP requests. Fortinet released security updates to address several vulnerabilities affecting FortiSandbox, FortiOS, FortiProxy, and FortiPortal. The most severe issue, tracked as CVE-2026-25089 (CVSS score of 9.8), is an OS command injection flaw in ...

      2026-06-19 02:12 UTC
    • web:securityonline.info

      An urgent patch fixes the critical CVE-2026-25089 FortiSandbox bug. Attackers can execute remote commands, so update your systems immediately.

      2026-06-19 02:12 UTC
    • web:threatprotect.qualys.com

      Threat actors are exploiting three security vulnerabilities in Fortinet FortiSandbox, tracked as CVE - 2026 -39808, CVE-2026-25089 , & CVE - 2026 -39813. Successful exploitation of the vulnerabilities could lead to OS command injection, authentication bypass, and privilege escalation.

      2026-06-19 02:12 UTC
    • web:www.helpnetsecurity.com

      Attackers have been spotted exploiting three vulnerabilities ( CVE - 2026 -39813, CVE - 2026 -39808, CVE-2026-25089 ) in FortiSandbox, a platform that other Fortinet security products depend on for threat ...

      2026-06-19 02:12 UTC
    • web:www.secpod.com

      A critical OS command injection vulnerability, CVE-2026-25089 , affects Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS deployments. The vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on affected devices by exploiting improper neutralization of special elements used in OS commands within the WEB UI.

      2026-06-19 02:12 UTC
    • web:www.tenable.com

      A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP ...

      2026-06-19 02:12 UTC
    • web:dailysecurityreview.com

      Fortinet has patched CVE-2026-25089 , a CVSS 9.1 critical OS command injection vulnerability in the FortiSandbox Web User Interface that allows an unauthenticated remote attacker to execute arbitrary commands on the affected appliance. No active exploitation has been reported, and the fix is available in FortiSandbox 4.4.9 and 5.0.6. CVE-2026-25089 : OS Command Injection in FortiSandbox's Web ...

      2026-06-19 02:12 UTC
    • web:www.thehackerwire.com

      CVE-2026-25089 is a Critical severity vulnerability (CVSS 9.8). A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through...

      2026-06-19 02:12 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2026-25089.json.

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-25089",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-10T03:58:38.447554Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-10T13:35:01.375Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:fortinet:fortisandbox:5.0.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:5.0.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:5.0.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:5.0.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:5.0.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:5.0.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.8:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.7:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.6:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.2.8:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.2.7:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.2.6:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.2.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.2.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.2.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.2.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.2.1:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "FortiSandbox",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "5.0.5",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "4.4.8",
                  "status": "affected",
                  "version": "4.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "4.2.8",
                  "status": "affected",
                  "version": "4.2.1",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:fortinet:fortisandboxcloud:5.0.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandboxcloud:5.0.4:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "FortiSandbox Cloud",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "5.0.5",
                  "status": "affected",
                  "version": "5.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:fortinet:fortisandboxpaas:5.0.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandboxpaas:5.0.4:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "FortiSandbox PaaS",
              "vendor": "Fortinet",
              "versions": [
                {
                  "lessThanOrEqual": "5.0.5",
                  "status": "affected",
                  "version": "5.0.4",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "Execute unauthorized code or commands",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-09T14:27:47.492Z",
            "orgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
            "shortName": "fortinet"
          },
          "references": [
            {
              "name": "https://fortiguard.fortinet.com/psirt/FG-IR-26-141",
              "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-141"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Upgrade to upcoming  FortiSandbox version 5.2.0 or above\nUpgrade to FortiSandbox version 5.0.6 or above\nUpgrade to FortiSandbox version 4.4.9 or above\nUpgrade to upcoming  FortiSandbox PaaS version 5.2.0 or above\nUpgrade to FortiSandbox PaaS version 5.0.6 or above\nFortinet remediated this issue in FortiSandbox Cloud version 5.2.0 (not released) and hence customers do not need to perform any action.\nFortinet remediated this issue in FortiSandbox Cloud version 5.0.6 (not released) and hence customers do not need to perform any action."
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "6abe59d8-c742-4dff-8ce8-9b0ca1073da8",
        "assignerShortName": "fortinet",
        "cveId": "CVE-2026-25089",
        "datePublished": "2026-06-09T14:27:47.492Z",
        "dateReserved": "2026-01-29T09:27:29.820Z",
        "dateUpdated": "2026-06-10T13:35:01.375Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }