Skip to main content
Back to Security Briefs

FortiSandbox vulnerabilities

2 published alerts for Fortinet FortiSandbox.

Actively exploited (KEV)

CVE-2026-25089

Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-25089). Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. CISA remediation due date: 2026-07-19. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Fortinet·FortiSandbox

Actively exploited (KEV)

CVE-2026-39808

Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-39808). Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. CISA remediation due date: 2026-07-19. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Fortinet·FortiSandbox