FortiSandbox Flaw CVE-2026-25089 Hits CISA KEV List
20 Jul 2026
A newly disclosed vulnerability in Fortinet's FortiSandbox—CVE-2026-25089—has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, with federal agencies given until July 19 to remediate. The flaw is already being actively exploited, and it's the third FortiSandbox vulnerability targeted in the wild within just two months.
What happened
CVE-2026-25089 is an unauthenticated command injection vulnerability (CWE-78) in FortiSandbox, Fortinet's malware analysis appliance. Because it requires no credentials, remote attackers can potentially execute arbitrary OS commands directly against affected systems.
CISA added the CVE to its KEV catalog on July 16, 2026, triggering a mandatory remediation deadline of July 19 for applicable Federal Civilian Executive Branch (FCEB) systems. Exploitation attempts were first reported by the threat-intel group Defused in mid-June, ahead of the formal KEV listing.
This is not an isolated incident. Two related FortiSandbox vulnerabilities—CVE-2026-39808 and CVE-2026-39813—were also observed being exploited in the wild earlier in the same window: KEVIntel flagged exploitation of CVE-2026-39808 on June 12, and Defused observed CVE-2026-39813 exploitation on June 15. Taken together, the report notes this marks the third FortiSandbox vulnerability exploited in the wild within two months, suggesting attackers have identified the product as a recurring target.
Severity scores don't fully agree
Sources differ on how severe these bugs actually are, depending on which Fortinet source you check:
- CVE-2026-25089: CVSS 9.8 per Fortinet's CNA record vs. 9.1 per Fortinet's PSIRT advisory
- CVE-2026-39808: CVSS 9.8 (CNA) vs. 9.1 (PSIRT)
- CVE-2026-39813: CVSS 9.8 (CNA) vs. 9.1 (PSIRT)
The report does not explain the reason for this discrepancy across all three vulnerabilities, but either score places these firmly in the critical range.
Why it matters beyond FortiSandbox
FortiSandbox doesn't operate in isolation—it feeds verdict data into other Fortinet products, including FortiGate, FortiMail, FortiWeb, and FortiProxy. A compromised FortiSandbox instance could therefore potentially degrade the accuracy of security verdicts across an organization's broader Fortinet deployment, not just the sandbox appliance itself.
The fix is available now
Fortinet has released patched versions that address all three vulnerabilities:
- FortiSandbox 4.4.9+ — resolves all three CVEs on the 4.4 branch
- FortiSandbox 5.0.6+ — resolves the applicable vulnerabilities on the 5.0 branch
Organizations running earlier versions should prioritize upgrading immediately, particularly given CISA's short remediation window and confirmed active exploitation.
What's still unclear
Several important details remain unreported:
- How many organizations or systems have actually been affected by exploitation attempts
- Whether CVE-2026-25089 exploitation has led to confirmed breaches, or only attempted access
- Whether the three vulnerabilities share common attack techniques or infrastructure
- Attribution—no threat actor identity has been disclosed
- Why CNA and PSIRT scoring diverges across all three CVEs
Why founders should care
For early-stage companies that rely on Fortinet appliances as part of their security stack, this pattern of repeated FortiSandbox exploitation likely warrants immediate attention rather than routine patch-cycle handling:
- If your infrastructure includes FortiSandbox, patching to 4.4.9+ or 5.0.6+ should probably be treated as urgent, given the KEV listing and confirmed in-the-wild exploitation.
- Because FortiSandbox verdicts feed into FortiGate, FortiMail, FortiWeb, and FortiProxy, founders using any of these integrated products may face broader exposure than a single-appliance vulnerability would suggest—even if FortiSandbox isn't your primary security tool.
- The recurrence of exploited FortiSandbox flaws (three in two months) could indicate that attackers see this product line as a soft target, meaning continued scrutiny and future disclosures are plausible.
- The gap between CNA (9.8) and PSIRT (9.1) severity scores is a reminder that founders assessing patch urgency should check multiple vendor sources rather than relying on a single score, since discrepancies can affect how internal teams triage risk.
Given the unauthenticated nature of the exploit and CISA's compressed deadline, teams running Fortinet infrastructure should treat this as a near-term action item rather than a background advisory.