DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-25089PUBLISHED: 2026-04-14
CRITICALCVE-2026-25089★ CISA KEV LISTED

Fortinet FortiSandbox Web UI OS Command Injection Unauthenticated RCE

VENDOR: Fortinet//PRODUCT: FortiSandbox / FortiSandbox Cloud / FortiSandbox PaaS
9.8
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
LIMITED EXPLOITATION

A second OS command injection vulnerability (CWE-78) in the FortiSandbox web UI, targeting the VNC session initiation feature, allows unauthenticated attackers to execute unauthorized commands via crafted HTTP requests. Active exploitation confirmed since mid-June 2026 and added to CISA KEV on July 16, 2026. The vulnerability can be chained with CVE-2026-39813 (path traversal/auth bypass) and CVE-2026-39808 in a two-step HTTP sequence to achieve unauthenticated root access on the appliance — the device intended to safely analyze malware for the enterprise.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSFortiSandbox 4.2.x (all versions), 4.4.0–4.4.8, 5.0.0–5.0.5; FortiSandbox Cloud 5.0.4–5.0.5; FortiSandbox PaaS 5.0.4–5.0.5; fixed in 4.4.9+ and 5.0.6+
  • https://hellorecon.com/blog/cve-2026-25089
  • https://sanjayseth.com/fortisandbox-cve-2026-25089-39808-39813-exploit-chain
  • https://threatprotect.qualys.com/2026/06/17/fortinet-fortisandbox-vulnerability-exploited-by-attackers-cve-2026-39808-cve-2026-25089-cve-2026-39813/
  • https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog
SHARE BRIEF:✕ Post on Xin Share on LinkedIn