Our takeCISA added CVE-2026-25089 (FortiSandbox OS command injection) to KEV. Unauthenticated remote code execution via crafted HTTP requests; patch the affected 4.4 and 5.0 branches now.Cyber Resilience desk
Sources (4)
- cccs · cccs
- cisa_kev · cisa_kev
- cisa_kev · cisa_kev
- infosec_mag · infosec_mag
What this means for you — Security leader:Two FortiSandbox OS command injection CVEs (2026-25089, 2026-39808) are now KEV-listed and exploited in the wild; federal deadline is July 19. Patch FortiSandbox 4.4.3-4.4.8 and 5.0.0-5.0.2 now, or isolate the management interface from the internet if you can't patch immediately.
What this means for you — Lean IT orgs:If you run FortiSandbox, unauthenticated attackers can already run commands on it — update to the fixed version now. If you don't know what FortiSandbox is, this one doesn't apply to you; skip it.
What this means for you — MSP:Check every client's FortiSandbox deployment (4.4.x, 5.0.x) against this KEV pair — unauthenticated command injection with active exploitation means this jumps the patch queue across your book. Flag any instance reachable from the internet as an emergency ticket, not routine maintenance.
What this means for you — Researcher:Two separate CVEs (2026-25089, 2026-39808) for OS command injection in the same FortiSandbox codebase, both unauthenticated and both now KEV — worth diffing the two advisories to see if they're the same root cause patched twice or genuinely distinct injection points.