CVE-2026-25089
exploitation · critical · Evidence score 90
- Vendor
- Fortinet
- Affected software
- Fortinet FortiSandbox
- Exploitation signal
- Listed in CISA Known Exploited Vulnerabilities
- EPSS
- 0.73603
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Provenance
CISA Known Exploited Vulnerabilities
16 July 2026, 10:00 AM AEST