What is CVE-2026-25089?
CVE-2026-25089 is an OS command injection vulnerability in Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that allows an unauthenticated attacker to execute unauthorized commands via specially crafted HTTP requests. Immediate patching is required as this vulnerability is being actively exploited.
Azərbaycanca: CVE-2026-25089, Fortinet-in FortiSandbox (o cümlədən Cloud və PaaS versiyaları) məhsullarında autentifikasiya olunmamış hücumçuya xüsusi hazırlanmış HTTP sorğuları vasitəsilə əməliyyat sistemində icazəsiz əmrlər icra etməyə imkan verən kritik bir zəiflikdir. Bu qüsurdan aktiv şəkildə istifadə edildiyi üçün dərhal Fortinet-in təqdim etdiyi yeniləmələr tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: Fortinet
FAQ2
Which Fortinet products are affected by CVE-2026-25089?
This vulnerability affects Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS.
Does exploiting CVE-2026-25089 require authentication?
No, this vulnerability allows an unauthenticated attacker to execute commands on the operating system via specially crafted HTTP requests.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.