CVE Research
sekurity-team
InSEKurity of the Week (CW26/2026): Fortinet FortiSandbox Unauthenticated OS Command Injection (CVE-2026-25089)
A critical OS command injection flaw in the FortiSandbox web GUI lets unauthenticated remote attackers run arbitrary system commands via crafted HTTP requests -- a foothold inside the very appliance built to detonate and analyze malware
Exploit
01