Vulnerabilities
3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-25089 | Unauthenticated OS Command Injection RCE in Fortinet FortiSandbox CVE-2026-25089 is an OS command injection flaw (CWE-78) in Fortinet FortiSandbox caused by improper neutralization of special elements in OS commands, allowing an unauthenticated attacker to execute unauthorized commands by sending specifically crafted HTTP requests to the product. The flaw is network-exploitable with no privileges or user interaction required (CVSS 3.1 score of 9.8), meaning any reachable instance — hardware/VM appliance, FortiSandbox Cloud, or FortiSandbox PaaS — is exposed to system-level command execution. Successful exploitation carries high impact to confidentiality, integrity, and availability on the sandbox itself and can serve as a foothold into the surrounding network. Organizations running FortiSandbox 5.0.0–5.0.5, 4.4.0–4.4.8, or 4.2 (all versions), as well as FortiSandbox Cloud 5.0.4–5.0.5 and FortiSandbox PaaS 5.0.4–5.0.5, are affected. The vulnerability is being actively exploited in the wild: CISA added it to the KEV catalog on 2026-07-16, EPSS assigns a 76.1% probability of exploitation within 30 days (100th percentile), and news coverage describes FortiSandbox bugs under active attack, though no public proof-of-concept is known. Do: Upgrade FortiSandbox to a release beyond the affected ranges — newer than 5.0.5, 4.4.8, and 4.2 — and update FortiSandbox Cloud and PaaS beyond 5.0.5, following Fortinet's PSIRT advisory for the exact fixed versions (not specified in this data). Until patched, restrict the FortiSandbox management interface from direct internet exposure and review appliance logs for signs of command-injection exploitation. Organizations subject to CISA's KEV requirements must apply vendor mitigations per BOD 26-04 timelines or discontinue cloud use of the product if mitigations are unavailable. | 9.8 | 76% | KEV |
| largelikely tens of thousands of deployments worldwide (10k–100k systems across appliance, VM, Cloud, and PaaS), with only a subset internet-exposed; exact install… | |
| CVE-2026-39808 | Unauthenticated OS Command Injection in Fortinet FortiSandbox 4.4 CVE-2026-39808 is an OS command injection flaw (CWE-78) in Fortinet FortiSandbox versions 4.4.0 through 4.4.8, caused by improper neutralization of special elements passed to OS commands. The vulnerability is network-reachable, requires no privileges or user interaction (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N), though CISA's description does not specify the exact entry point that a remote unauthenticated attacker abuses to trigger it. Successful exploitation lets the attacker execute unauthorized code or commands on the appliance, with high impact to confidentiality, integrity, and availability. Any organization running FortiSandbox 4.4.0-4.4.8 is affected; these sandboxing appliances are typically deployed as add-ons to enterprise FortiGate security estates. The flaw was added to CISA's KEV on 2026-07-16, and press coverage describes critical FortiSandbox bugs coming under active attack, so in-the-wild exploitation should be assumed. Do: Upgrade all FortiSandbox appliances out of the affected 4.4.0-4.4.8 range to a fixed release per Fortinet's advisory, prioritizing internet-exposed units and complying with the CISA KEV required action (added 2026-07-16) and BOD 26-04 guidance. Until patched, restrict network access to the appliance's management and analysis interfaces and triage for signs of command execution such as unexpected processes or outbound connections. Confirm the specific fixed 4.4.x build in Fortinet's PSIRT advisory before scheduling upgrades. | 9.8 | 93% | KEV PoC |
| moderate≈1,000-10,000 deployed FortiSandbox appliances (est.), of which a low thousands are likely internet-exposed | |
| CVE-2025-68686 | Unauthenticated Info-Exposure Bypass of Symlink Patch in Fortinet FortiOS CVE-2025-68686 is a sensitive-information-exposure flaw (CWE-200) in Fortinet FortiOS that allows a remote, unauthenticated attacker to bypass the vendor's patch for the symbolic-link (symlink) persistency mechanism seen in some post-exploitation cases. It is triggered by crafted HTTP requests sent to a device that has already been compromised through another vulnerability at the filesystem level, for example where symlinks were planted to maintain access to files. By bypassing the patch, the attacker can keep retrieving sensitive information from an otherwise remediated FortiGate device. Any organization running an affected FortiOS release is potentially affected; the CISA data does not enumerate specific versions, so administrators should consult Fortinet's advisory for the affected branches. The flaw was added to CISA's KEV catalog on 2026-07-27, confirming real-world exploitation, and EPSS assigns a 29.6% probability of exploitation within 30 days (98th percentile), with ransomware use currently unknown. Do: Patch affected FortiOS devices per Fortinet's current advisory, following BOD 26-04 timelines for federal agencies (apply mitigations per vendor instructions or discontinue use where mitigations are unavailable). Because this flaw defeats the earlier symlink-persistence fix, re-check previously remediated devices for residual or recreated symlinks and hunt for indicators of prior filesystem-level compromise, such as unexpected symlinks and anomalous SSL-VPN activity. Review logs for crafted HTTP requests and prioritize internet-facing FortiGate assets for patching and triage. | 5.9 | 30% | KEV |
| mass~300,000+ internet-exposed FortiGate/FortiOS devices |