DigiNews

Tech Watch by Johan Denoyer

← Back to articles

CVE-2026-25089: FortiSandbox Unauthenticated OS Command Injection — How to Find Exposed Instances on Your Network

Quality: 8/10 Relevance: 9/10

Summary

CVE-2026-25089 is an unauthenticated OS command injection vulnerability in FortiSandbox's web UI with a high severity that has seen active exploitation. This article details the vulnerability, affected versions, exploitation activity, and recommended remediation steps, including patching and monitoring Fortinet integrations. It also notes CISA KEV listing and guidance for incident response.

🚀 Service construit par Johan Denoyer