Find notable cyber news and cases, enriched with sources, timelines, and signals.

FortiSandbox unauthenticated command injection (CVE-2026-25089)

Vulnerability
First reported
Last updated
Happening score
H score 47
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-25089 is an unauthenticated operating system command injection in FortiSandbox-related products that was seen in active exploitation over the past 24 hours. The flaw can let an attacker send crafted HTTP requests to execute unauthorized commands on exposed systems.

Related Happenings

FortiBleed multi-vendor brute-force wave

Exploitation Wave
H score75 First: 23.06.2026 21:20 Last: 23.06.2026 21:20 Sources 1

About this happening: A multi-vendor brute-force wave tied to FortiBleed is hitting Fortinet, Synology, Sophos, Citrix, RDWeb, and MS-SQL targets, expanding the risk from one firewall-focus...

FortigateSniffer FortiOS packet-sniffer credential-harvesting tool

Malware Activity
H score72 First: 22.06.2026 23:01 Last: 22.06.2026 23:01 Sources 1

About this happening: FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...

Fortinet FortiSandbox multi-CVE exploitation wave

Exploitation Wave
H score49 First: 16.06.2026 12:19 Last: 16.06.2026 12:19 Sources 1

How related: In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours.

About this happening: Fortinet FortiSandbox is facing an active exploitation wave that puts affected deployments at risk of unauthenticated remote code execution and privilege escalat...

PAN-OS / Prisma Access GlobalProtect authentication bypass (CVE-2026-0257, actively exploited)

Vulnerability
H score19 First: 30.05.2026 09:41 Last: 30.05.2026 09:41 Sources 1

About this happening: PAN-OS and Prisma Access are affected by CVE-2026-0257, an authentication bypass in the GlobalProtect portal and gateway that can let attackers establish an ...

FortiClient EMS improper access control flaw (CVE-2026-35616)

Vulnerability
H score59 First: 05.04.2026 21:45 Last: 05.04.2026 21:45 Sources 1

About this happening: CVE-2026-35616 is an actively exploited improper access control flaw in FortiClient Enterprise Management Server (EMS) that lets unauthenticated attackers execute code...

Latest development: 28.05.2026 18:26

Attackers were already abusing CVE-2026-35616 against FortiClient EMS in May 2026. The flaw provided pre-auth API access bypass and privilege escalation before remediation in 7.4.7 and later.

Timeline

  1. 16.06.2026 13:30 2 articles · 29d ago

    Defused Cyber observes exploitation of three FortiSandbox vulnerabilities

    Initial Disclosure

    Defused Cyber said it observed exploitation of Fortinet FortiSandbox vulnerabilities CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours. The flaws include a FortiSandbox JRPC API path traversal issue in CVE-2026-39813, operating system command injection in CVE-2026-39808 and CVE-2026-25089, and CVE-2026-25089 was described as having a faulty exploit with no working public exploit disclosed.

    Show sources