Tagged: FortiSandbox
2 posts · browse all tags
-
The Chain Nobody's Advisory Describes: FortiSandbox's Three CVEs, Read Together
A follow-up to this site's CVE-2026-25089 post: a threat intel firm reports that bug chained with two more FortiSandbox CVEs (file-read plus privesc) for unauthenticated root in practice. What's confirmed by Fortinet's own advisories versus what's one firm's account, held carefully apart.
-
Start VNC, Start a Shell: Inside CVE-2026-25089 on FortiSandbox
CVE-2026-25089 is a CVSS 9.8 unauthenticated OS command injection in FortiSandbox's Web UI, actively exploited since mid-June and on CISA's KEV list since July. No password, no CVE chaining, just a crafted request to a device that already sits inline reading everything suspicious you feed it.