CVE-2026-25089: FortiSandbox Unauthenticated Command Injection Added To CISA KEV

TL;DR

CISA has officially added CVE-2026-25089, a severe unauthenticated command injection flaw in FortiSandbox, to its KEV list. This marks a significant security concern for organizations using the product. Details about active exploits are still emerging.

The Cybersecurity and Infrastructure Security Agency (CISA) has officially added CVE-2026-25089, a critical unauthenticated command injection vulnerability in FortiSandbox, to its Known Exploited Vulnerabilities list. This inclusion indicates confirmed exploitation activity and highlights the severity of the flaw for organizations relying on Fortinet’s security products.

CVE-2026-25089 was discovered in FortiSandbox, a security product used for malware analysis and threat detection. The vulnerability allows attackers to execute arbitrary commands on affected systems without authentication, potentially leading to remote code execution and system compromise.

According to CISA, the vulnerability has been actively exploited in the wild, prompting the agency to update its KEV list to warn organizations of the risk. Fortinet has released a security patch addressing the issue, urging users to apply updates immediately.

Details about the specific attack vectors or the scope of active exploitation are still emerging, but CISA’s inclusion of the flaw indicates confirmed malicious activity targeting unpatched systems.

At a glance
updateWhen: announced March 2026, ongoing developme…
The developmentCISA has listed CVE-2026-25089, a critical security flaw in FortiSandbox, in its KEV, after confirming exploitation attempts targeting unpatched systems.

Implications of CVE-2026-25089 for Security Posture

The addition of CVE-2026-25089 to the KEV underscores the critical nature of the vulnerability, which could enable attackers to gain remote control over affected systems without credentials. This poses a significant risk for organizations using FortiSandbox, especially if they have not yet applied the latest security updates.

Exploitation of this flaw could lead to data breaches, disruption of security operations, or further lateral movement within compromised networks. The fact that CISA has confirmed active exploitation elevates the urgency for affected entities to prioritize patching and mitigation efforts.

Security Patch, 2 Pcs Reflective Security Hook and Loop Patch for Vest Printed Letters Embroidery Patches for Officer Guard Custom Uniforms Vest, Jacket, Carrier, Bag, Hat (Black, 1 Small and 1 Large)

Security Patch, 2 Pcs Reflective Security Hook and Loop Patch for Vest Printed Letters Embroidery Patches for Officer Guard Custom Uniforms Vest, Jacket, Carrier, Bag, Hat (Black, 1 Small and 1 Large)

【Package Content】The package contains two security patches for vest, one small (5.5 x 2.5 inches) and one large…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background on FortiSandbox and Recent Vulnerabilities

FortiSandbox is a widely deployed security solution used by organizations to analyze and detect malware threats. Historically, vulnerabilities in Fortinet products have attracted attention from cybercriminals and nation-state actors, prompting frequent security advisories and patches.

CVE-2026-25089 is the latest in a series of vulnerabilities affecting Fortinet’s security portfolio, following past issues that have sometimes been exploited in targeted attacks. The vulnerability was identified through ongoing threat intelligence efforts, leading to its inclusion in CISA’s KEV list.

“The inclusion of CVE-2026-25089 in the KEV list reflects confirmed exploitation activity and the urgent need for affected organizations to apply security patches.”

— CISA spokesperson

NetAlly CyberScope Air Wi-Fi Edge Network Vulnerability Scanner (Wireless Only Version). Validate Edge Infrastructure Hardening, Hunt Down Rogue Devices, Investigate Suspect RF Interference

NetAlly CyberScope Air Wi-Fi Edge Network Vulnerability Scanner (Wireless Only Version). Validate Edge Infrastructure Hardening, Hunt Down Rogue Devices, Investigate Suspect RF Interference

Portable, handheld form factor – Take it anywhere for on-site security testing. This field-ready tool gives you visibility…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Extent of Ongoing Exploitation and Attack Methods

While CISA confirms active exploitation of CVE-2026-25089, specific details about the scope, scale, and attack techniques remain limited. It is not yet clear how widespread the exploitation is or which threat actors are involved.

Further information about the methods used in attacks or targeted sectors is still emerging, and security researchers are monitoring developments closely.

The Practice of Network Security Monitoring: Understanding Incident Detection and Response

The Practice of Network Security Monitoring: Understanding Incident Detection and Response

Used Book in Good Condition

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Expected Security Updates and Monitoring Efforts

Organizations using FortiSandbox should verify they have applied the latest patches issued by Fortinet. CISA and other security agencies will likely continue monitoring for exploitation attempts and issuing additional guidance.

Security teams are advised to review their systems for signs of compromise, enhance monitoring, and prepare incident response plans in case of targeted attacks exploiting this vulnerability.

Further updates from Fortinet and cybersecurity authorities are anticipated as more details about active exploitation become available.

The CERT Guide to Insider Threats: How to Prevent, Detect, and Respond to Information Technology Crimes (Theft, Sabotage, Fraud) (SEI Series in Software Engineering)

The CERT Guide to Insider Threats: How to Prevent, Detect, and Respond to Information Technology Crimes (Theft, Sabotage, Fraud) (SEI Series in Software Engineering)

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What is CVE-2026-25089?

CVE-2026-25089 is a critical vulnerability in FortiSandbox that allows unauthenticated attackers to execute arbitrary commands on affected systems, potentially leading to remote code execution.

Why has CISA added this vulnerability to KEV?

CISA has added CVE-2026-25089 to its Known Exploited Vulnerabilities list because it has confirmed active exploitation in the wild, posing a significant security risk.

How can organizations protect themselves?

Organizations should immediately apply the security patches released by Fortinet addressing CVE-2026-25089, review their systems for signs of compromise, and enhance monitoring for suspicious activity.

Is this vulnerability being exploited widely?

While CISA confirms active exploitation, the full extent and scope of attacks are still unclear. Security agencies continue to monitor the situation.

What should affected organizations do now?

They should prioritize patching affected systems, review security logs, and prepare incident response plans. Further guidance is expected from cybersecurity authorities.

Source: hn

You May Also Like

Xiaomi, Fujian, China Surges In Global Coverage

Xiaomi, based in Fujian, China, experiences a significant increase in international coverage, with 16 mentions in recent global media reports.

Pandoc Lua Filters

Pandoc introduces Lua filters to improve document processing, offering users customizable and powerful formatting options in open-source workflows.

Rumanien Hackerangriff

A confirmed cyberattack originating from Romania has affected key infrastructure sectors, raising concerns over cybersecurity and national security.

Semgrep: GLM 5.2 beats Claude in our Cyber Benchmarks

Open-weight GLM 5.2 from Zhipu AI beats Claude in vulnerability detection, approaching Semgrep’s multimodal pipeline performance in security tests.