FortiSandbox unauthenticated command injection (CVE-2026-25089)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-25089 is an unauthenticated operating system command injection in FortiSandbox-related products that was seen in active exploitation over the past 24 hours. The flaw can let an attacker send crafted HTTP requests to execute unauthorized commands on exposed systems.
Related Happenings
FortiBleed multi-vendor brute-force wave
Exploitation Wave
H score75
First: 23.06.2026 21:20
Last: 23.06.2026 21:20
Sources 1
About this happening:
A multi-vendor brute-force wave tied to FortiBleed is hitting Fortinet, Synology, Sophos, Citrix, RDWeb, and MS-SQL targets, expanding the risk from one firewall-focus...
FortiBleed multi-vendor brute-force wave
Exploitation WaveAbout this happening: A multi-vendor brute-force wave tied to FortiBleed is hitting Fortinet, Synology, Sophos, Citrix, RDWeb, and MS-SQL targets, expanding the risk from one firewall-focus...
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware Activity
H score72
First: 22.06.2026 23:01
Last: 22.06.2026 23:01
Sources 1
About this happening:
FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware ActivityAbout this happening: FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...
Fortinet FortiSandbox multi-CVE exploitation wave
Exploitation Wave
H score49
First: 16.06.2026 12:19
Last: 16.06.2026 12:19
Sources 1
How related:
In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours.
About this happening:
Fortinet FortiSandbox is facing an active exploitation wave that puts affected deployments at risk of unauthenticated remote code execution and privilege escalat...
Fortinet FortiSandbox multi-CVE exploitation wave
Exploitation WaveHow related: In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours.
About this happening: Fortinet FortiSandbox is facing an active exploitation wave that puts affected deployments at risk of unauthenticated remote code execution and privilege escalat...
PAN-OS / Prisma Access GlobalProtect authentication bypass (CVE-2026-0257, actively exploited)
Vulnerability
H score19
First: 30.05.2026 09:41
Last: 30.05.2026 09:41
Sources 1
About this happening:
PAN-OS and Prisma Access are affected by CVE-2026-0257, an authentication bypass in the GlobalProtect portal and gateway that can let attackers establish an ...
PAN-OS / Prisma Access GlobalProtect authentication bypass (CVE-2026-0257, actively exploited)
VulnerabilityAbout this happening: PAN-OS and Prisma Access are affected by CVE-2026-0257, an authentication bypass in the GlobalProtect portal and gateway that can let attackers establish an ...
FortiClient EMS improper access control flaw (CVE-2026-35616)
Vulnerability
H score59
First: 05.04.2026 21:45
Last: 05.04.2026 21:45
Sources 1
About this happening:
CVE-2026-35616 is an actively exploited improper access control flaw in FortiClient Enterprise Management Server (EMS) that lets unauthenticated attackers execute code...
FortiClient EMS improper access control flaw (CVE-2026-35616)
VulnerabilityAbout this happening: CVE-2026-35616 is an actively exploited improper access control flaw in FortiClient Enterprise Management Server (EMS) that lets unauthenticated attackers execute code...
Latest development: 28.05.2026 18:26
Attackers were already abusing CVE-2026-35616 against FortiClient EMS in May 2026. The flaw provided pre-auth API access bypass and privilege escalation before remediation in 7.4.7 and later.
Timeline
-
16.06.2026 13:30 2 articles · 29d ago
Defused Cyber observes exploitation of three FortiSandbox vulnerabilities
Initial DisclosureDefused Cyber said it observed exploitation of Fortinet FortiSandbox vulnerabilities CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours. The flaws include a FortiSandbox JRPC API path traversal issue in CVE-2026-39813, operating system command injection in CVE-2026-39808 and CVE-2026-25089, and CVE-2026-25089 was described as having a faulty exploit with no working public exploit disclosed.
Show sources
- Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week — thehackernews.com — 16.06.2026 13:30
- Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week — thehackernews.com — 16.06.2026 13:30