Skip to main content

CVE detail

CVE-2026-25089

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

CVSS 9.8 · CriticalBuzz score 73.3KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 73.3

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 28.3 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
28.3
16 evidence mentions in the snapshot
Diversity score
20.0
10 sources across 5 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
8
within the 30d window
Peak daily
4
highest bucket

Evidence

Source links by recency

Newest mentions first
16 source links · newest first
  • lity, making it difficult to distinguish what’s “AI-slop” and what’s a real working exploit. Recently, we saw this with CVE-2026-25089 , an OS Command Injection vulnerability in Fortinet FortiSandbox. For example, our sensors will pick up on the novel exploitation and flag it to us, but then we have to spend time researching and trying to reproduce the

    newswww.helpnetsecurity.comJul 30, 2026, 6:00 AM
  • CISA) added Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities (KEV) catalog . CVE-2026-25089 (CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-39808 (CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-58644 (CVSS score of 9.8) Microsoft Share

    newssecurityaffairs.comJul 18, 2026, 11:49 AM
  • endars after CISA confirmed a pair of critical FortiSandbox bugs are being actively exploited. The two bugs, tracked as CVE-2026-39808 and CVE-2026-25089, both carry CVSS scores of 9.1 and affect FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. According to Fortinet, they are OS command injection flaws that allow unauthenticated attackers to ex

    newswww.theregister.comJul 17, 2026, 11:58 AM
  • in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) has warned. The vulnerabilities, tracked as CVE-2026-39808 and CVE-2026-25089 are both critical, with a severity rating (CVSS) of 9.1 each. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog on July 16, suggesting evidence of observed exploitation in the wild.

    newswww.infosecurity-magazine.comJul 17, 2026, 9:45 AM
  • y remote code execution (RCE) vulnerability in Microsoft SharePoint, the US cybersecurity agency CISA warns. Tracked as CVE-2026-58644 (CVSS score of 9.8) and fixed as part of Microsoft’s July 2026 Patch Tuesday updates, the flaw is described as a deserialization of untrusted data issue. “In a network-based attack, an attacker authenticated as at least

    newswww.securityweek.comJul 17, 2026, 7:15 AM
  • bilities in the Fortinet FortiSandbox threat detection platform. These two critical-severity security flaws (tracked as CVE-2026-39808 and CVE-2026-25089 ) were addressed by Fortinet on April 14 and June 9, respectively. As the company detailed in security advisories issued at the time, successful exploitation allows unauthenticated threat actors to ex

    newswww.bleepingcomputer.comJul 17, 2026, 7:03 AM
  • Linked URL: https://hellorecon.com/blog/cve-2026-25089 | Posted by slvnx | 33 points | 1 comments

    communitynews.ycombinator.comJul 16, 2026, 10:07 PM
  • ee new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability These

    governmentwww.cisa.govJul 16, 2026, 12:00 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: A hardware neural network backdoor that hides in plain sight Deep learning systems on edge devices often rely on third-party-designed FPGAs and ASICs for performance and efficiency, creating supply chain risks. Researchers from the University of Tennessee and the University of Florida developed HAMLOCK, a backdoor attack that splits malicious functionality between hardware and software, making detection more difficult. Onspring … More →

    newswww.helpnetsecurity.comJun 21, 2026, 8:00 AM
  • SOCRadar has detected 30,000 compromised Fortinet firewalls that expose networks to hacking.

    newswww.securityweek.comJun 17, 2026, 6:53 AM
  • Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from threat intelligence company Defused, which said that the exploit for one of the flaws is vibecoded, and likely faulty. The vulnerabilities Fortinet disclosed CVE-2026-39813 and CVE-2026-39808 in April 2026. The former is a path traversal vulnerability in … More →

    newswww.helpnetsecurity.comJun 16, 2026, 3:27 PM
  • Three FortiSandbox flaws, including one patched last week, are being actively exploited, highlighting the shrinking window for defenders. Cybersecurity firm Defused Cyber confirmed it’s seen active exploitation of three vulnerabilities in Fortinet FortiSandbox within a 24-hour window. Two of them had patches sitting available since April. The third got fixed last week, which, apparently, wasn’t […]

    newssecurityaffairs.comJun 16, 2026, 2:21 PM
  • Fortinet patched a critical FortiSandbox vulnerability that could let unauthenticated attackers remotely execute commands via crafted HTTP requests. Fortinet released security updates to address several vulnerabilities affecting FortiSandbox, FortiOS, FortiProxy, and FortiPortal. The most severe issue, tracked as CVE-2026-25089 (CVSS score of 9.8), is an OS command injection flaw in FortiSandbox products. The vulnerability could […]

    newssecurityaffairs.comJun 11, 2026, 9:51 AM
  • Two OS command injection flaws can be exploited remotely, without authentication, for arbitrary code execution.

    newswww.securityweek.comJun 10, 2026, 8:50 AM
  • No excerpt available.

    Mitigationwww.cisa.govJun 9, 2026, 4:16 PM
  • https://fortiguard.fortinet.com/psirt/FG-IR-26-141fortiguard.fortinet.com

    No excerpt available.

    Vendor Advisoryfortiguard.fortinet.comJun 9, 2026, 4:16 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence