CVE-2026-25089: Fortinet FortiSandbox RCE Flaw
🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical OS command injection vulnerability in Fortinet FortiSandbox (including its cloud and PaaS variants) allows an unauthenticated attacker to run arbitrary commands simply by sending crafted HTTP requests — no login required. This is actively being exploited in the wild, as confirmed by CISA’s addition to its Known Exploited Vulnerabilities catalogue. The potential impact is severe, as FortiSandbox is a security control itself, meaning compromise could blind an organisation to other threats. ...