## Overview
CISA added CVE-2026-25089 to its Known Exploited Vulnerabilities (KEV) list on July 16, 2026. This vulnerability affects Fortinet's FortiSandbox products, including FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, and FortiSandbox Cloud versions 5.0.4 through 5.0.5. The addition to the KEV list signals a federal deadline for remediation, emphasizing the urgency of addressing this flaw.
## Technical Details
The vulnerability is an OS command injection issue. It allows unauthenticated attackers to execute unauthorized commands by sending specifically crafted HTTP requests. This flaw arises from improper neutralization of special elements used in OS commands. The affected versions include FortiSandbox 4.2 across all versions and FortiSandbox PaaS 5.0.4 through 5.0.5.
## Impact
Successful exploitation of this vulnerability can lead to significant security risks. Attackers can execute arbitrary commands on the affected systems, potentially compromising sensitive data and system integrity. The CVSS score for this vulnerability is 9.8, indicating critical severity. Evidence of exploitation has prompted CISA to act, highlighting the need for immediate attention from organizations using these products.
## Mitigation
Fortinet has released patches to address this vulnerability. Organizations using affected versions should prioritize applying these updates. Additionally, monitoring network traffic for unusual HTTP requests can help detect potential exploitation attempts. It is crucial to review security policies and ensure that only authorized users have access to FortiSandbox systems.
CSURFACE Threat Sensor