Critical CVSS 9.8 OS command injection vulnerability in Fortinet FortiSandbox (4.4.0-4.4.9) allows remote code execution. Actively exploited in the wild.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| fortisandbox | 4.4.0 | 4.4.9 | vulnerable |
Immediately download and install the latest firmware updates from the Fortinet Support Portal that specifically address the FG-IR-26-100 advisory.
Ensure all FortiSandbox deployments running versions 4.4.0 through 4.4.9 are upgraded to version 4.4.10 or the latest available stable release to eliminate the vulnerable code path.
Minimize the attack surface by placing FortiSandbox management interfaces behind a VPN or hardware firewall and restricting network access to known, trusted administrative IP addresses.
Perform a forensic triage of system logs for unusual shell command execution or unauthorized administrative access, adhering to CISA’s Forensics Triage Requirements and BOD 26-04 guidance.
Detection should focus on identifying unusual OS command execution patterns within FortiSandbox system logs. Monitor for unexpected outbound network connections originating from the appliance, which may indicate a reverse shell or data exfiltration. Additionally, inspect web server and API logs for suspicious payloads containing shell metacharacters such as semicolons, pipes, or backticks. Security teams should also audit administrative account logs for unauthorized logins or the creation of new, unrecognized local users.
Experience superior visibility and a simpler approach to cyber risk management