{"id":270124,"date":"2026-06-11T05:51:00","date_gmt":"2026-06-11T09:51:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/06\/11\/fortinet-patched-a-new-critical-fortisandbox-flaw\/"},"modified":"2026-06-11T07:30:23","modified_gmt":"2026-06-11T11:30:23","slug":"fortinet-patched-a-new-critical-fortisandbox-flaw","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/06\/11\/fortinet-patched-a-new-critical-fortisandbox-flaw\/","title":{"rendered":"Fortinet patched a new critical FortiSandbox flaw"},"content":{"rendered":"<p><a href=\"https:\/\/securityaffairs.com\/193509\/security\/fortinet-patched-a-new-critical-fortisandbox-flaw.html?amp\">Fortinet patched a new critical FortiSandbox flaw<\/a><\/p>\n<p><a href=\"https:\/\/securityaffairs.com\/193509\/security\/fortinet-patched-a-new-critical-fortisandbox-flaw.html?amp\">https:\/\/securityaffairs.com\/193509\/security\/fortinet-patched-a-new-critical-fortisandbox-flaw.html?amp<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-06-11 05:51:00<\/a><\/p>\n<p>Source Domain: <a href=\"securityaffairs.com\">securityaffairs.com<\/a><\/p>\n<p><h2>Fortinet patched a new critical FortiSandbox flaw<\/h2>\n<\/p>\n<p>\t\t\t\t\t\t\t<span> Pierluigi Paganini<\/span><br \/>\n\t\t\t\t\t\t\t<span><img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> June 11, 2026<\/span><\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2019\/11\/fortinet-logo.jpg?fit=730%2C480&#038;ssl=1\" alt=\"\"\/><\/p>\n<h2 class=\"wp-block-heading\">Fortinet patched a critical FortiSandbox vulnerability that could let unauthenticated attackers remotely execute commands via crafted HTTP requests.<\/h2>\n<p class=\"wp-block-paragraph\">Fortinet released security updates to address several vulnerabilities affecting FortiSandbox, FortiOS, FortiProxy, and FortiPortal. The most severe issue, tracked as CVE-2026-25089 (CVSS score of 9.8), is an OS command injection flaw in FortiSandbox products. <\/p>\n<p class=\"wp-block-paragraph\">The vulnerability could allow remote, unauthenticated attackers to send specially crafted HTTP requests and execute arbitrary commands on affected devices.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAn improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.\u201d reads the advisory.<\/p>\n<p class=\"wp-block-paragraph\">Adham El Karn of Fortinet Product Security team discovered the vulnerability.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerability impacts the following products and versions:<\/p>\n<ul class=\"wp-block-list\">\n<li>FortiSandbox 5.0.0 through 5.0.5 (Upgrade to 5.0.6 or above)<\/li>\n<li>FortiSandbox 4.4.0 through 4.4.8 (Upgrade to 4.4.9 or above)<\/li>\n<li>FortiSandbox Cloud 5.0.4 through 5.0.5 (Upgrade to 5.0.6 or above)<\/li>\n<li>FortiSandbox PaaS 5.0.4 through 5.0.5 (Upgrade to 5.0.6 or above)<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">The company also patched two medium-severity vulnerabilities affecting FortiOS, FortiProxy, and the FortiPortal API. The flaws could allow authenticated users to execute scripts or access sensitive network configuration information. At the time of disclosure, the vendor said it was not aware of any in-the-wild exploitation targeting these vulnerabilities and urged customers to apply the available security updates.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Follow me on Twitter:\u00a0<\/strong><strong>@securityaffairs<\/strong><strong>\u00a0and\u00a0<\/strong><strong>Facebook<\/strong><strong>\u00a0and\u00a0<\/strong><strong>Mastodon<\/strong><strong\/><\/p>\n<p class=\"wp-block-paragraph\"><strong>Pierluigi\u00a0Paganini<\/strong><strong\/><\/p>\n<p...<\/strong>\n<p><a href=\"https:\/\/securityaffairs.com\/193509\/security\/fortinet-patched-a-new-critical-fortisandbox-flaw.html?amp\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fortinet patched a new critical FortiSandbox flaw https:\/\/securityaffairs.com\/193509\/security\/fortinet-patched-a-new-critical-fortisandbox-flaw.html?amp Publish Date: 2026-06-11 05:51:00 Source Domain: securityaffairs.com&#8230;<\/p>\n","protected":false},"author":1,"featured_media":270125,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/securityaffairs.com\/wp-content\/uploads\/2019\/11\/fortinet-logo.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[27],"class_list":["post-270124","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/270124"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=270124"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/270124\/revisions"}],"predecessor-version":[{"id":270126,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/270124\/revisions\/270126"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/270125"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=270124"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=270124"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=270124"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}