DIRAS TAKE
Urgent: CISA placed this issue on the Known Exploited Vulnerabilities list with a July 19, 2026 remediation deadline, and public exploit code exists—treat internet-exposed FortiSandbox instances as high priority to isolate or mitigate immediately.
What is CVE-2026-25089?
Attackers can send crafted HTTP requests to Fortinet FortiSandbox and execute arbitrary OS commands, giving full control of affected appliances; this is tracked as CVE-2026-25089. Affected releases include FortiSandbox 5.0.0–5.0.5, FortiSandbox 4.4.0–4.4.8, FortiSandbox 4.2.1–4.2.8, and FortiSandbox Cloud/PaaS 5.0.4–5.0.5. The vulnerability requires no authentication and only network access to the vulnerable FortiSandbox HTTP service to be exploited. The weakness is classified as CWE-78 (OS Command Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Fortinet FortiSandbox are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| FortiSandbox 5.x | 5.0.0 – 5.0.5 | |
| FortiSandbox 4.x | 4.4.0 – 4.4.8 | |
| FortiSandbox 4.x | 4.2.1 – 4.2.8 | |
| FortiSandbox Cloud 5.x | 5.0.4 – 5.0.5 | |
| FortiSandbox PaaS 5.x | 5.0.4 – 5.0.5 |
Is CVE-2026-25089 being exploited?
CISA added CVE-2026-25089 to the Known Exploited Vulnerabilities catalog on 2026-07-16; U.S. federal agencies were required to remediate by 2026-07-19. Public exploit code for the vulnerability is available.
How to fix CVE-2026-25089
- Isolate or block internet access to FortiSandbox HTTP interfaces until mitigations are applied
- Follow Fortinet’s official guidance and mitigations immediately (apply vendor instructions)
- Monitor FortiSandbox logs and network traffic for suspicious commands and indicators of compromise
- If mitigations are unavailable, discontinue use of affected systems or move workloads to unaffected/segregated infrastructure
Frequently asked questions
Is CVE-2026-25089 being actively exploited?
CISA added CVE-2026-25089 to the Known Exploited Vulnerabilities catalog on 2026-07-16 and set a remediation deadline of 2026-07-19 for U.S. federal agencies; public exploit code is also available.
Which FortiSandbox versions are affected by CVE-2026-25089?
FortiSandbox releases affected are 5.0.0–5.0.5, FortiSandbox 4.4.0–4.4.8, FortiSandbox 4.2.1–4.2.8, and FortiSandbox Cloud/PaaS 5.0.4–5.0.5 as listed in the vendor advisory.
Is there a patch for CVE-2026-25089?
No vendor-fixed versions are listed in the provided facts; follow Fortinet’s published mitigations and consider isolating affected appliances.
Does CVE-2026-25089 require authentication?
No — the vulnerability allows unauthenticated attackers to send crafted HTTP requests to FortiSandbox and execute OS commands.
References
- nvd.nist.gov/vuln/detail/CVE-2026-25089
- cve.org/CVERecord?id=CVE-2026-25089
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-25089
- fortiguard.fortinet.com/psirt/FG-IR-26-141
- All Fortinet CVEs on CVE Radar
- CVEs published in September 2026