Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A critical unauthenticated OS command injection vulnerability (CVE-2026-25089, CVSS 9.8) has been disclosed in Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. An attacker with network access to the management interface can execute arbitrary operating system commands without credentials, potentially gaining full control of the appliance. Organizations running affected on-premises versions (FortiSandbox 4.4.0-4.4.8, 5.0.0-5.0.5) or using the cloud/PaaS offerings should prioritize patching as an emergency change control process, completing remediation before the end of the active exploit window.

Author

Tech Jacks Solutions