InFeeo
Language

CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV(nvd.nist.gov)

×
Link preview NVD - CVE-2026-25089 Fortinet FortiSandbox contains a critical OS command injection vulnerability (CVSS 9.8) in the web UI allowing unauthenticated remote code execution via crafted HTTP requests. Third FortiSandbox CVE exploited in 2026. CISA KEV listed. Find exposed instances with RECON. RECON · nvd.nist.gov
Fortinet FortiSandbox contains a critical OS command injection vulnerability (CVSS 9.8) in the web UI allowing unauthenticated remote code execution via crafted HTTP requests. Third FortiSandbox CVE exploited in 2026. CISA KEV listed. Find exposed instances with RECON.

Comments

Log in Log in to comment.

No comments yet.