PoC Index

CVE-2026-25089

KEVCRITICAL 9.8EPSS 76.1%

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
76.11% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2026-07-16
Published
2026-06-09
Updated
2026-07-17

Proof-of-concept exploits (3)

References

Related