CVE-2026-25089
KEV
🔴 Łataj teraz
Wstrzyknięcie poleceń w Fortinet FortiSandbox umożliwia zdalne wykonanie nieautoryzowanych komend.
CVSS
9.8
EPSS
36.1%
Exploit
weaponized
Vendor
fortinet
Opis źródłowy (NVD)
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 36.1% |
| Opublikowano (NVD) | 2026-06-09 16:16:39 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-17 05:16:38 UTC |
Referencje
- https://fortiguard.fortinet.com/psirt/FG-IR-26-141 (psirt@fortinet.com) [Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-25089 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]