FortiSandbox CVE-2026-25089 actively exploited, CISA sets federal patch deadline
US federal agencies had until today to patch Fortinet FortiSandbox after CISA confirmed active exploitation. CVE-2026-25089 lets an unauthenticated attacker run OS commands via a crafted HTTP request, no login required. Fortinet $FTNT shipped fixes June 9. Per BleepingComputer.
US federal agencies faced a hard deadline today to patch Fortinet $FTNT FortiSandbox appliances after CISA confirmed the flaw is being exploited in the wild. The vulnerability, tracked as CVE-2026-25089, is an operating-system command injection weakness: an unauthenticated attacker can send a specially crafted HTTP request and run commands directly on the device, without any login or credentials. It affects FortiSandbox, FortiSandbox Cloud and the PaaS version. Fortinet released fixes on June 9, but CISA added the flaw to its Known Exploited Vulnerabilities catalog and, under Binding Operational Directive 26-04, ordered federal agencies to patch by Sunday, July 19. A second FortiSandbox flaw, CVE-2026-39808, was flagged in the same order. The detail worth noting: a FortiSandbox appliance exists to inspect suspicious files and detonate malware in isolation. When that system itself is compromised, the tool meant to catch intrusions becomes the entry point. Organizations running these appliances should confirm they are on a patched build and review logs for unexpected command execution. Reported by BleepingComputer, based on the CISA directive.