Coverage of CVE-2026-25089, the FortiSandbox second-order OS command injection vulnerability affecting FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS.
CISA added two Fortinet FortiSandbox command-injection flaws to its exploited-vulnerabilities catalog on July 16, giving federal agencies until July 19 to remediate. Security teams should patch affected FortiSandbox systems, restrict management access, and review logs and connected credentials if exposure existed before the upgrade.