• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-25089: pre-auth remote code execution in Fortinet FortiSandbox

Attackers can send crafted HTTP requests to Fortinet FortiSandbox and execute arbitrary OS commands, giving full control of affected appliances; this is tracked as CVE-2026-25089. Affected releases include FortiSandbox 5.0.0–5.0.5, FortiSandbox 4.4.0–4.4.8, FortiSandbox 4.2.1–4.2.8, and FortiSandbox Cloud/PaaS 5.0.4–5.0.5. The vulnerability requires no authentication and only network access to the vulnerable FortiSandbox HTTP service to be exploited.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.76112
CWE
CWE-78
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA placed this issue on the Known Exploited Vulnerabilities list with a July 19, 2026 remediation deadline, and public exploit code exists—treat internet-exposed FortiSandbox instances as high priority to isolate or mitigate immediately.

What is CVE-2026-25089?

Attackers can send crafted HTTP requests to Fortinet FortiSandbox and execute arbitrary OS commands, giving full control of affected appliances; this is tracked as CVE-2026-25089. Affected releases include FortiSandbox 5.0.0–5.0.5, FortiSandbox 4.4.0–4.4.8, FortiSandbox 4.2.1–4.2.8, and FortiSandbox Cloud/PaaS 5.0.4–5.0.5. The vulnerability requires no authentication and only network access to the vulnerable FortiSandbox HTTP service to be exploited. The weakness is classified as CWE-78 (OS Command Injection).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Fortinet FortiSandbox are affected?

BRANCHAFFECTEDFIXED
FortiSandbox 5.x5.0.0 – 5.0.5
FortiSandbox 4.x4.4.0 – 4.4.8
FortiSandbox 4.x4.2.1 – 4.2.8
FortiSandbox Cloud 5.x5.0.4 – 5.0.5
FortiSandbox PaaS 5.x5.0.4 – 5.0.5

Is CVE-2026-25089 being exploited?

CISA added CVE-2026-25089 to the Known Exploited Vulnerabilities catalog on 2026-07-16; U.S. federal agencies were required to remediate by 2026-07-19. Public exploit code for the vulnerability is available.

How to fix CVE-2026-25089

  1. Isolate or block internet access to FortiSandbox HTTP interfaces until mitigations are applied
  2. Follow Fortinet’s official guidance and mitigations immediately (apply vendor instructions)
  3. Monitor FortiSandbox logs and network traffic for suspicious commands and indicators of compromise
  4. If mitigations are unavailable, discontinue use of affected systems or move workloads to unaffected/segregated infrastructure

Frequently asked questions

Is CVE-2026-25089 being actively exploited?

CISA added CVE-2026-25089 to the Known Exploited Vulnerabilities catalog on 2026-07-16 and set a remediation deadline of 2026-07-19 for U.S. federal agencies; public exploit code is also available.

Which FortiSandbox versions are affected by CVE-2026-25089?

FortiSandbox releases affected are 5.0.0–5.0.5, FortiSandbox 4.4.0–4.4.8, FortiSandbox 4.2.1–4.2.8, and FortiSandbox Cloud/PaaS 5.0.4–5.0.5 as listed in the vendor advisory.

Is there a patch for CVE-2026-25089?

No vendor-fixed versions are listed in the provided facts; follow Fortinet’s published mitigations and consider isolating affected appliances.

Does CVE-2026-25089 require authentication?

No — the vulnerability allows unauthenticated attackers to send crafted HTTP requests to FortiSandbox and execute OS commands.

References