CVE-2026-25089: critical vulnerability in FortiSandbox actively exploited
Critical flaw (CVSS 9.8) in FortiSandbox allows command execution without authentication. Already in CISA's KEV catalog. How to protect yourself.
CVE-2026-25089: critical vulnerability in FortiSandbox actively exploited
In short
CVE-2026-25089 is a critical vulnerability (CVSS 9.8) [1] discovered in Fortinet's FortiSandbox, which allows an attacker without needing credentials to execute unauthorized commands on the system via specially crafted HTTP requests [1]. It affects several versions of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS [1]. The vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog [2], meaning that its real-world use by attackers has already been detected. If your company uses FortiSandbox in any of its forms, the first thing you should do today is identify which version you have deployed and check whether it falls within the affected range.
What it is and why it matters
This is an OS Command Injection vulnerability: a flaw in how the application processes certain input that allows an attacker to insert commands that the system executes without control [1]. In this case, the issue affects FortiSandbox, Fortinet's solution designed precisely to analyze and detect threats, which adds a relevant nuance: if the security analysis system itself becomes compromised, the organization loses a key piece of its defense [1].
What makes this vulnerability deserve priority attention is not just its critical severity score [1], but that its active exploitation is already confirmed according to CISA's KEV catalog [2]. This places it in a different category from theoretical vulnerabilities: it is not a hypothetical risk, but one that attackers are already taking advantage of in the real world [2].
Who is affected
According to official information, the following FortiSandbox variants are affected [1]:
- FortiSandbox versions 5.0.0 through 5.0.5
- FortiSandbox versions 4.4.0 through 4.4.8
- FortiSandbox 4.2, all versions
- FortiSandbox Cloud, from version 5.0.4 to 5.0.5
- FortiSandbox PaaS, from version 5.0.4 to 5.0.5
This covers both on-premise deployments and Fortinet-managed cloud services, so it's worth reviewing the entire inventory of licenses and contracts, not just the physical equipment installed on your own infrastructure.
How to know if you're vulnerable
The first step is to confirm which version of FortiSandbox (or its Cloud/PaaS variants) your organization has deployed and compare it against the affected ranges listed above [1]. Both production and testing environments should be reviewed, since this type of tool is often also deployed in lab or malware analysis environments that sometimes fall outside the usual patching radar.
In addition to reviewing versions internally, it's advisable to check which administrative services and ports are exposed to the internet, as that is typically the vector exploited by this type of flaw. At OCIRIA we use our own exposed surface radar to help companies identify Fortinet assets visible from the outside before third parties do.
How to protect yourself
- Identify all FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS systems in your organization, including test and lab environments.
- Verify the installed version against the affected ranges published by Fortinet and NVD [1].
- Apply the security updates provided by Fortinet as soon as they are available for your specific version, prioritizing this system given that it is a vulnerability with confirmed active exploitation [1][2].
- If you cannot update immediately, restrict access to the administration interface to trusted networks only and review access logs for anomalous HTTP requests.
- Check for indicators of compromise on the affected systems, especially if they have been exposed to the internet without restrictions.
- Document the patching and verification process as part of your vulnerability management, given that this is a case already included in CISA's KEV catalog [2].
Frequently asked questions
Do you need credentials to exploit this vulnerability?
No. The official description states that an unauthenticated attacker can execute unauthorized commands via specially crafted HTTP requests [1].
Is this vulnerability currently being exploited?
Yes, the vulnerability is listed in the Known Exploited Vulnerabilities (KEV) catalog maintained by CISA [2].
Does it only affect local installations of FortiSandbox?
No. Versions of FortiSandbox Cloud and FortiSandbox PaaS within the indicated range are also affected [1], so it's advisable to review Fortinet-managed services as well.
What should I do if I can't apply the patch right away?
Reduce exposure by limiting access to the administration interface and monitor system activity while you plan the update, given that this is a critical flaw with confirmed active exploitation [1][2].
Sources
- [1] https://nvd.nist.gov/vuln/detail/CVE-2026-25089
- [2] https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json