Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Windows 11 Update KB5094126 Freezes Systems, Forces BitLocker
June 15, 2026
Critical Wazuh Flaw Lets Attackers Tamper Alerts &
June 15, 2026
SecSuite: AI Tool for OSINT, Web AI-powered Security
June 15, 2026
Home/CyberSecurity News/Fortinet FortiSandbox Vulnerability: Attackers Execute
CyberSecurity News

Fortinet FortiSandbox Vulnerability: Attackers Execute

Fortinet has disclosed a critical security vulnerability in its FortiSandbox product line. This flaw could allow unauthenticated remote attackers to execute arbitrary OS commands through the web...

David kimber
David kimber
June 9, 2026 2 Min Read
18 0

Fortinet has disclosed a critical security vulnerability in its FortiSandbox product line. This flaw could allow unauthenticated remote attackers to execute arbitrary OS commands through the web interface.

The flaw, tracked as CVE-2026-25089 and assigned a CVSSv3 score of 9.1 (Critical), affects multiple versions of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS deployments.

The vulnerability stems from an improper neutralization of special elements used in an OS command (CWE-78) commonly known as OS command injection present in the FortiSandbox Web UI.

By sending specifically crafted HTTP requests, a remote, unauthenticated attacker can exploit this flaw to execute unauthorized commands on the underlying system.

Because no authentication is required to trigger the vulnerability, the attack complexity is low, and the potential blast radius is significant. Successful exploitation can result in the full compromise of the affected system’s confidentiality, integrity, and availability, which explains its near-maximum CVSS score.

The advisory was discovered and reported internally by Adham El Karn of Fortinet’s Product Security team and published on June 9, 2026, under the internal reference FG-IR-26-141.

Affected Versions and Fixes

The vulnerability impacts the following product versions:

Product Affected Versions Fix
FortiSandbox 5.0.0 – 5.0.5 Upgrade to 5.0.6 or above
FortiSandbox 4.4.0 – 4.4.8 Upgrade to 4.4.9 or above
FortiSandbox Cloud 5.0.4 – 5.0.5 Upgrade to 5.0.6 or above
FortiSandbox PaaS 5.0.4 – 5.0.5 Upgrade to 5.0.6 or above

FortiSandbox 5.2, FortiSandbox Cloud 4.4, FortiSandbox Cloud 5.2, FortiSandbox PaaS 4.4, FortiSandbox PaaS 5.2, and FortiSandbox PaaS 23.4 are not affected by this vulnerability.

While there are currently no reports of active exploitation in the wild, the unauthenticated nature of this attack vector makes it a high-priority target for threat actors.

FortiSandbox is widely deployed in enterprise environments as a malware analysis and threat detection platform, meaning a successful compromise could undermine an organization’s entire threat detection pipeline, giving attackers a strategic foothold.

Recommended Actions

Security teams are strongly advised to take the following steps immediately:

  • Upgrade affected FortiSandbox installations to version 5.0.6 or 4.4.9 or above
  • Restrict web UI access to trusted IP ranges as a temporary mitigation
  • Monitor logs for anomalous HTTP requests targeting the FortiSandbox web interface
  • Review Fortinet’s official advisory at the Fortinet PSIRT portal for further guidance

Organizations still running any affected 4.4.9 or 5.0.6 builds should treat this as an urgent patching priority given the critical severity and zero-authentication requirement.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarePatchSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Google Chrome 0-Day Exploit: Update Browser Immediately

Next Post

CyberCheck360 Catches Malicious Link Byp DKIM DMARC

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Palo Alto: GlobalProtect VPN Vulnerability Act Warns Actively
June 15, 2026
152 Chrome Extensions Maliciously Hide Ad Tracking
June 14, 2026
Maine AG Takes Data Breach Portal Offline After Fake
June 14, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us