๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability
Summary
Fortinet FortiSandbox has a critical vulnerability that lets unauthenticated attackers run unauthorized commands (OS command injection, where an attacker can execute system commands on the affected system) by sending specially crafted HTTP requests. This vulnerability is actively being exploited by attackers. Organizations using FortiSandbox must apply vendor-provided patches or mitigations by July 19, 2026, or stop using the product if fixes are unavailable.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions from Fortinet. Follow CISA's BOD 26-04 guidance for patching prioritization. For cloud services, follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. See vendor security advisory at https://fortiguard.fortinet.com/psirt/FG-IR-26-141 for specific patch or mitigation details.
Vulnerability Details
EPSS: 23.4%
Yes
๐ฅ Actively Exploited
July 15, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-25089
First tracked: July 16, 2026 at 02:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%