Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CVE-2026-25089 is a CVSS 9.8 unauthenticated OS command injection flaw in Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS, allowing a network-adjacent attacker to execute arbitrary OS commands without credentials. The 83.7th-percentile EPSS score indicates elevated exploitation probability, and the vulnerability is not yet in CISA KEV — meaning defensive attention may lag the actual risk level. Emergency patching is required for on-premises affected versions.

Author

Tech Jacks Solutions