CVE-2026-25089CISA KEVEPSS p99.3%

CVE-2026-25089Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet / FortiSandbox

Description

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS69.83% probability of exploitation · percentile 99.3% · 2026-08-03T12:00:16Z
Last modified2026-07-23

CISA KEV entry

Added to KEV: 2026-07-16

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-53679
CVE
CVE-2025-53949
CVE
CVE-2025-52436
CVE
CVE-2026-26083
CVE
CVE-2025-25256
CVE
Fortinet FortiWeb OS Command Injection Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.