Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2823 articles · 164161 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-25089EXPLOITEDPATCHED
fortinet · fortisandbox

CVE-2026-25089: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F

Description

CVE-2026-25089 allows a remote, unauthenticated attacker to execute arbitrary commands on vulnerable appliances.

Affected Products

VendorProductVersions
fortinetfortisandbox5.0.0, 4.4.0, 4.2.1, 5.0.4, 5.0.4, FortiSandbox 4.4.0 - 4.4.8, FortiSandbox 5.0.0 - 5.0.5, FortiAnalyzer Cloud 7.6.2 - 7.6.4, FortiManager Cloud 7.6.2 - 7.6.4, FortiDDoS-F 7.2.1 - 7.2.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
fortinetfortisandbox cloudmitre_affected90%
fortinetfortisandbox paasmitre_affected90%
fortinetfortisandboxcert_advisory90%
fortinetfortisandbox_cloudcve_cpe95%
fortinetfortisandbox_paascve_cpe95%

References

  • https://fortiguard.fortinet.com/psirt/FG-IR-26-141

Related News (9 articles)

Tier D
Heise Security2h ago
Angriffe auf FortiSandbox-Schwachstellen
→ No new info (linked only)
Tier D
SecurityWeek7h ago
3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs
→ No new info (linked only)
Tier D
The Hacker News6d ago
Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
→ No new info (linked only)
Tier D
SecurityWeek7d ago
Critical Vulnerabilities Patched in Fortinet, Ivanti Products
→ No new info (linked only)
Tier D
Heise Security7d ago
Fortinet schließt Befehlsschmuggel-Lücke in FortiSandbox und mehr
→ No new info (linked only)
Tier B
BSI Advisories7d ago
[NEU] [hoch] Fortinet FortiSandbox: Schwachstelle ermöglicht Befehlsausführung
→ No new info (linked only)
Tier C
VulDB7d ago
CVE-2026-25089 | Fortinet FortiSandbox/FortiSandbox Cloud/FortiSandbox PaaS HTTP os command injection (FG-IR-26-141)
→ No new info (linked only)
Tier B
CCCS Canada7d ago
Fortinet security advisory (AV26-568)
→ No new info (linked only)
Tier A
Fortinet PSIRT8d ago
Second-Order OS Command Injection via JSON Input on start vnc feature
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
4.4.9
CWECWE-78, CWE-77, CWE-287, CWE-269, CWE-122, CWE-89
PublishedJun 9, 2026
Last enriched7h agov6
Tags
os command injectionauthentication bypassprivilege escalationheap-based buffer overflowsql injectionfortinetcritical vulnerability
Trending Score94
Source articles9
Independent7
Info Completeness11/14
Missing: epss, kev, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-39808EXPKEV
CVE-2026-39808: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
Trending: 152
CRITICALCVE-2026-39813EXPKEV
CVE-2026-39813: A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.
Trending: 147
CRITICALCVE-2026-35616EXPKEV
CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
Trending: 71
CRITICALCVE-2026-26083
CVE-2026-26083: A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, Fo
Trending: 66
MEDIUMCVE-2025-61624EXP
CVE-2025-61624: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet For
Trending: 56

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 9, 2026
Discovered by ZDM
Jun 9, 2026
Updated: affectedVersions, patchAvailable
Jun 9, 2026
Updated: affectedVersions
Jun 10, 2026
Updated: affectedVersions, activelyExploited
Jun 10, 2026
Updated: cvssEstimate, exploitAvailable, patchAvailable
Jun 10, 2026
Actively Exploited
Jun 10, 2026
Exploit Available
Jun 10, 2026
Patch Available
Jun 10, 2026
Updated: description
Jun 17, 2026

Version History

v6
Last enriched 7h ago
v6Tier D7h ago

Updated description to specify that CVE-2026-25089 allows arbitrary command execution and noted that it was patched in June 2026.

description
via SecurityWeek
v5Tier D7d ago

Updated CVSS score to 9.8, added affected version 4.4.9, marked exploit as available, and confirmed patch available for 4.4.9.

cvssEstimateexploitAvailablepatchAvailable
via SecurityWeek
v4Tier D7d ago

Updated patch version to 5.0.6, added new affected versions, and marked the vulnerability as actively exploited.

affectedVersionsactivelyExploited
via Heise Security
v3Tier D7d ago

Updated affected versions to include 4.4.9, confirmed patch available as 5.0.6, and marked exploit as available and actively exploited.

affectedVersions
via Heise Security
v2Tier A7d ago

Added affected version 5.2 and updated patch available to 5.0.6.

affectedVersionspatchAvailable
via Fortinet PSIRT
v17d ago

Initial creation