Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-25089

Published 2026-06-09
Updated 2 months ago
Vendor/s
Fortinet
Product/s
FortiSandbox
Version/s
4.2.0 > 4.2.8
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

Fortinet FortiSandbox is vulnerable to a critical (9.8) unauthenticated OS command injection. Patch immediately to prevent remote code execution.

CPE

Fortinet logo
Fortinet
Product Version Start Version End (excl.) Status
fortisandbox 4.2.0 4.2.8 vulnerable
fortisandbox 4.4.0 4.4.9 vulnerable
fortisandbox 5.0.0 5.0.6 vulnerable
fortisandbox_cloud 5.0.4 5.0.6 vulnerable
fortisandbox_paas 5.0.4 5.0.6 vulnerable

Related weakness (CWE)

CWE-78

Remediation plan

1

Apply official patches

Consult Fortinet's PSIRT advisory (FG-IR-26-141) and apply the recommended firmware updates for your specific FortiSandbox model and deployment type, including Physical, Cloud, and PaaS versions.

2

Update affected systems

Upgrade FortiSandbox to version 5.0.6, 4.4.9, or higher. For users on the 4.2 branch, migrate to a supported, patched version as all 4.2 versions are identified as vulnerable.

3

Restrict access

Limit network access to the FortiSandbox management interface to trusted internal IP addresses only. Use a firewall or VPN to ensure the appliance is not exposed to the public internet.

4

Monitor for exploitation

Conduct forensic triage of FortiSandbox logs in accordance with CISA's BOD 26-04 guidance. Look for suspicious HTTP requests containing shell metacharacters or unauthorized system-level configuration changes.

Detection Guidance

Security teams should inspect HTTP access logs for FortiSandbox management interfaces, looking for suspicious characters associated with OS command injection (e.g., ';', '|', '&', '$()') within request parameters. Monitor for unusual outbound network connections originating from the FortiSandbox appliance itself, which may indicate a reverse shell. Additionally, check system integrity logs for unauthorized administrative users or unexpected process execution outside of normal sandbox operations.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management