What is CVE-2026-25089?
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
Timeline
- 2026-06-09Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-17First covered in a defend.network daily briefing
- 2026-07-16Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-07-19CISA federal remediation deadline (BOD 22-01)
- 2026-07-23NVD record last updated
CISA Known Exploited Vulnerability
Fortinet FortiSandbox OS Command Injection Vulnerability
Affected product
Fortinet FortiSandbox
NVD also lists CPE entries for: Fortinet Fortisandbox, Fortinet Fortisandbox Cloud, Fortinet Fortisandbox Paas
Remediation Steps
- Apply the vendor patch immediately per Fortinet's security advisory
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 3 of July 2026 (July 20 – 26)
- Vulnerability Priority Report – Week 2 of July 2026 (July 13 – 19)
- Vulnerability Priority Report – Week 3 of June 2026 (June 15 – 21)
- Vulnerability Priority Report – Week 2 of June 2026 (June 8 – 14)
- WordPress, OpenSSL, Fortinet zero-days: patches shipped and KEV escalations (2026-07-18)
- Fortinet actively exploited; Rokarolla targets 217 banking apps; Google Vertex AI flaw (2026-06-17)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.