Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3162 articles · 183088 vulns · 36/41 feeds (7d)
← Back to list
9.1
CVE-2026-25089EXPLOITEDPATCHED
fortinet · fortisandbox

CVE-2026-25089: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

Affected Products

VendorProductVersions
fortinetfortisandbox5.0.0, 4.4.0, 4.2.1, 5.0.4, 5.0.4, 5.0.5, 4.4.8, 4.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
fortinetfortisandbox cloudmitre_affected90%
fortinetfortisandbox paasmitre_affected90%
fortinetfortisandboxcert_advisory90%
fortinetfortisandbox_cloudcve_cpe95%
fortinetfortisandbox_paascve_cpe95%

References

  • https://fortiguard.fortinet.com/psirt/FG-IR-26-141

Related News (13 articles)

Tier D
Help Net Security2d ago
200 new CVEs a day and no realistic way to patch them all
→ No new info (linked only)
Tier D
BleepingComputer10d ago
New InfraTrust report reveals infrastructure flaws admins should patch first
→ No new info (linked only)
Tier D
Infosecurity Magazine15d ago
CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities
→ No new info (linked only)
Tier E
Hacker News15d ago
CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV
→ No new info (linked only)
Tier D
Heise Security45d ago
Angriffe auf FortiSandbox-Schwachstellen
→ No new info (linked only)
Tier D
SecurityWeek45d ago
3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs
→ No new info (linked only)
Tier D
The Hacker News52d ago
Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
→ No new info (linked only)
Tier D
SecurityWeek52d ago
Critical Vulnerabilities Patched in Fortinet, Ivanti Products
→ No new info (linked only)
Tier D
Heise Security52d ago
Fortinet schließt Befehlsschmuggel-Lücke in FortiSandbox und mehr
→ No new info (linked only)
Tier B
BSI Advisories52d ago
[NEU] [hoch] Fortinet FortiSandbox: Schwachstelle ermöglicht Befehlsausführung
→ No new info (linked only)
Tier C
VulDB52d ago
CVE-2026-25089 | Fortinet FortiSandbox/FortiSandbox Cloud/FortiSandbox PaaS HTTP os command injection (FG-IR-26-141)
→ No new info (linked only)
Tier B
CCCS Canada53d ago
Fortinet security advisory (AV26-568)
→ No new info (linked only)
Tier A
Fortinet PSIRT53d ago
Second-Order OS Command Injection via JSON Input on start vnc feature
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
4.4.9
CWECWE-78
PublishedJun 9, 2026
Last enriched15d agov8
Tags
os command injectionauthentication bypassprivilege escalationheap-based buffer overflowsql injectionfortinetcritical vulnerabilityunauthenticatedweb interfacerce
Trending Score84
Source articles13
Independent11
Info Completeness11/14
Missing: epss, kev, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-59835
CVE-2026-59835: A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 th
Trending: 9
MEDIUMCVE-2026-59837
CVE-2026-59837: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM
Trending: 7
MEDIUMCVE-2026-23573
CVE-2026-23573: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi
Trending: 6
MEDIUMCVE-2026-59840
CVE-2026-59840: A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v
Trending: 6
MEDIUMCVE-2026-59839
CVE-2026-59839: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0
Trending: 6

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 9, 2026
Discovered by ZDM
Jun 9, 2026
Updated: affectedVersions, patchAvailable
Jun 9, 2026
Updated: affectedVersions
Jun 10, 2026
Updated: affectedVersions, activelyExploited
Jun 10, 2026
Updated: cvssEstimate, exploitAvailable, patchAvailable
Jun 10, 2026
Updated: description
Jun 17, 2026
Updated: affectedVersions, tags
Jul 17, 2026
Actively Exploited
Jul 17, 2026
Exploit Available
Jul 17, 2026
Patch Available
Jul 17, 2026
Updated: affectedVersions
Jul 17, 2026

Version History

v8
Last enriched 15d ago
v8Tier D15d ago

Updated affected versions to include complete ranges (5.0.5, 4.4.8, 4.2 instead of incomplete list) and added patch version 5.0.6 for versions 5.0.x and FortiSandbox Cloud/PaaS

affectedVersions
via Infosecurity Magazine
v7Tier E15d ago

Updated description with technical details on the "start VNC" feature and JSON payload exploitation, increased CVSS score to 9.8, added affected versions 4.2.x, and updated patch information to 4.4.9+ and 5.0.6+.

affectedVersionstags
via Hacker News
v6Tier D45d ago

Updated description to specify that CVE-2026-25089 allows arbitrary command execution and noted that it was patched in June 2026.

description
via SecurityWeek
v5Tier D52d ago

Updated CVSS score to 9.8, added affected version 4.4.9, marked exploit as available, and confirmed patch available for 4.4.9.

cvssEstimateexploitAvailablepatchAvailable
via SecurityWeek
v4Tier D52d ago

Updated patch version to 5.0.6, added new affected versions, and marked the vulnerability as actively exploited.

affectedVersionsactivelyExploited
via Heise Security
v3Tier D52d ago

Updated affected versions to include 4.4.9, confirmed patch available as 5.0.6, and marked exploit as available and actively exploited.

affectedVersions
via Heise Security
v2Tier A53d ago

Added affected version 5.2 and updated patch available to 5.0.6.

affectedVersionspatchAvailable
via Fortinet PSIRT
v153d ago

Initial creation