First published · Last updated
CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute commands via crafted HTTP requests. CISA's advisory requires applying vendor mitigations and following BOD 26-04 and forensics triage guidance.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 8/10
- Geographic reach
- 4/10
- Global importance
- 5/10
- Impact magnitude
- 4/10
- Positivity
- 2/10
- Urgency
- 7/10
Why it matters
The flaw permits unauthenticated OS command execution, and CISA directs stakeholders to apply mitigations or discontinue use if mitigations are unavailable.

