CVE-2026-25089 · Critical · CISA KEV
FortiSandbox OS Command Injection: Unauthenticated RCE, Actively Exploited
Threat Engine Auto-Feed · data current as of 2026-07-17
CVE-2026-25089 is an OS command injection vulnerability in Fortinet FortiSandbox products, allowing unauthenticated attackers to execute arbitrary commands via crafted HTTP requests. This flaw is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has a high EPSS percentile, indicating significant exploitation probability.
- CVSS:
- EPSS percentile: 0.98302
- Exploitation pressure: 84/100 (Critical)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 98th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
An OS command injection vulnerability occurs when an application constructs a system command using user-supplied input without proper sanitization. This allows an attacker to inject and execute arbitrary operating system commands on the underlying server, potentially leading to full system compromise.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations using Fortinet FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS
- Financial services organizations (due to assessed targeting by FIN7, LockBit affiliates, APT38)
- Technology sector organizations (due to assessed targeting by APT29, Scattered Spider)
Misconfigurations that escalate it
- Lack of network segmentation for FortiSandbox instances, allowing direct access from untrusted networks
- Insufficient logging and monitoring of HTTP requests to FortiSandbox devices
High-impact scenarios
- Complete compromise of the FortiSandbox appliance, potentially leading to data exfiltration or further network penetration
- Disruption of sandbox analysis capabilities, impacting an organization's ability to detect advanced threats
- Lateral movement within the network if the compromised sandbox has elevated privileges or access to internal resources
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor FortiSandbox logs for unusual command execution attempts or unexpected HTTP request patterns
- Look for unauthorized outbound connections originating from FortiSandbox devices
- Scan for indicators of compromise (IOCs) related to known exploitation of CVE-2026-25089
Contain
- Isolate affected FortiSandbox instances from the network if immediate patching is not feasible
- Block suspicious IP addresses attempting to interact with FortiSandbox devices
- Review and restrict network access to FortiSandbox management interfaces
Patch
- Apply vendor-provided security updates for Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS immediately
Frontier verdict — Critical
Critical priority due to active exploitation in the wild (CISA KEV) and high EPSS, enabling unauthenticated OS command injection.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.