ctipilot.ch

FortiSandbox unauthenticated OS command injection in VNC handler (CVSS 9.8); dropped from brief - no inclusion gate cleared

cve · CVE-2026-25089

Coverage timeline
3
first 2026-06-11 → last 2026-06-22
Peak priority
high
1 high · 2 notable
Sources cited
11
8 hosts
Sections touched
3
trending-vulnerabilities, updates, weekly-vuln-rollup
Co-occurring entities
3
see Related entities below
ATT&CK techniques
1
pinned v19.1 · see below

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-06-12/cve-2026-25089-fortinet-fortisandbox-unauthenticated-os-comm · ATT&CK page ↗

Story timeline

  1. 2026-06-22CVE-2026-25089 / CVE-2026-39808 / CVE-2026-39813 — FortiSandbox: three critical flaws exploited in one 24-hour window
    weekly-vuln-rollup
  2. 2026-06-17FortiSandbox — three critical flaws now exploited simultaneously, including the previously disclosure-only CVE-2026-25089
    updates
  3. 2026-06-12CVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1
  • updates1
  • weekly-vuln-rollup1

Source distribution

  • msrc.microsoft.com4 (36%)
  • advisories.ncsc.nl1 (9%)
  • attack.mitre.org1 (9%)
  • ccb.belgium.be1 (9%)
  • helpnetsecurity.com1 (9%)
  • oracle.com1 (9%)
  • security-hub.ncsc.admin.ch1 (9%)
  • securityaffairs.com1 (9%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

External references

NVD · cve.org · CISA KEV

All cited sources (11)

Entries about FortiSandbox unauthenticated OS command injection in VNC handler (CVSS 9.8); dropped from brief - no inclusion gate cleared (3)

2026-06-22 · view entry permalink →

NOTABLECVE-2026-39808 +2exploited

CVE-2026-25089 / CVE-2026-39808 / CVE-2026-39813 — FortiSandbox: three critical flaws exploited in one 24-hour window

What was disclosure-only on 06-12 became active exploitation this week: Defused Cyber reported three FortiSandbox flaws exploited within a single 24-hour window — a JRPC OS command injection (CVE-2026-39808, 9.8), a JRPC path-traversal/auth-bypass (CVE-2026-39813, 9.1), and the web-UI command injection (CVE-2026-25089, 9.8) (Security Affairs; daily 06-17). FortiSandbox supplies the verdicts FortiGate, FortiMail, FortiProxy and FortiClient consume, so a compromised sandbox can suppress detection across the dependent Fortinet stack. The CVE-2026-25089 in-the-wild exploit appears AI-generated and faulty yet still finds traction against unpatched interfaces; Fortinet has not officially confirmed exploitation. Patch all three and restrict management-interface exposure.

What was disclosure-only on 06-12 became active exploitation this week: Defused Cyber reported three FortiSandbox flaws exploited within a single 24-hour window — a JRPC OS command injection (CVE-2026-39808, 9.8), a JRPC path-traversal/auth-bypass (CVE-2026-39813, 9.1), and the web-UI command …

ctipilot v2 brief (migrated)
vulnerability22 Jun 00:14Zmulti-sourceOpen finding ↗

2026-06-17 · view entry permalink →

HIGHCVE-2026-39808 +2exploitedupdate

FortiSandbox — three critical flaws now exploited simultaneously, including the previously disclosure-only CVE-2026-25089

UPDATE · originally covered CVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8) (2026-06-12)

When CVE-2026-25089 was covered on 06-12 it was disclosure-only. Threat-intel firm Defused Cyber has now reported active exploitation of three FortiSandbox flaws within a single 24-hour window — CVE-2026-39808 (CVSS 9.8, JRPC OS command injection), CVE-2026-39813 (CVSS 9.1, JRPC path traversal / auth bypass), both with patches available since April 2026, and CVE-2026-25089 (CVSS 9.8, web-UI command injection), patched 2026-06-09 (Security Affairs, 2026-06-16).

FortiSandbox supplies sandboxed file verdicts that FortiGate, FortiMail, FortiProxy and FortiClient consume to make blocking decisions, so a compromised sandbox can suppress detection across the dependent Fortinet stack (Help Net Security, 2026-06-16). The CVE-2026-25089 exploit seen in the wild appears AI-generated and is assessed as faulty, yet still finds traction against unpatched deployments — evidence that exposed, unpatched FortiSandbox interfaces remain. Fortinet has not yet officially confirmed exploitation. Patch all three; until then, restrict management-interface exposure and watch FortiSandbox web-UI/JRPC access logs for unauthenticated external POSTs.

UPDATE (originally covered 2026-06-12): When CVE-2026-25089 was covered on 06-12 it was disclosure-only.

ctipilot v2 brief (migrated)
vulnerability17 Jun 05:14Zmulti-sourceOpen finding ↗

2026-06-12 · view entry permalink →

CVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)

Fortinet patched CVE-2026-25089 (CWE-78, internal reference FG-IR-26-141) on 9 June: the FortiSandbox web interface's "start VNC" handler passes attacker-controlled JSON to the underlying OS without sanitisation, allowing a remote unauthenticated attacker to achieve second-order command injection via a crafted HTTP request (NCSC-NL, 2026-06-11). Affected: FortiSandbox 5.0.0–5.0.5 and 4.4.0–4.4.8 (plus corresponding Cloud/PaaS builds); fixed in 5.0.6 and 4.4.9. CCB Belgium urges immediate patching and warns that the public availability of a proof-of-concept exploit increases the likelihood of exploitation (CCB Belgium, 2026-06-11). No in-the-wild exploitation is reported, and the management interface is not meant to be internet-reachable — but with a public PoC available, a compromised FortiSandbox hands an attacker every file your SOC submits for detonation, plus a trusted foothold inside the security stack (T1190). Discovered internally by Fortinet's product-security team; the FortiGuard PSIRT page was unreachable in this run (.

CVE Summary Table

CVE Product CVSS EPSS KEV Exploited Patch Source
CVE-2026-35273 Oracle PeopleSoft PeopleTools 8.61/8.62 (PSEMHUB) 9.8 n/a No Yes — zero-day, UNC6240 Out-of-band alert 2026-06-10 Oracle
CVE-2026-49261 MariaDB Server (Galera wsrep_notify_cmd) 10.0 n/a No No 11.8.8 / 11.4.12 / 10.11.18 / 10.6.27 NCSC-CH
CVE-2026-45657 Windows kernel (TCP/IP) 9.8 n/a No No June 2026 cumulative MSRC
CVE-2026-26142 Nuance PowerScribe 9.8 n/a No No June 2026 update MSRC
CVE-2026-47643 Azure Stack Edge 9.8 n/a No No June 2026 update MSRC
CVE-2026-48579 Exchange Online 9.1 n/a No No Service-side, no customer action MSRC
CVE-2026-25089 Fortinet FortiSandbox 9.8 n/a No PoC public 5.0.6 / 4.4.9 NCSC-NL
vulnerability12 Jun 05:00Zmulti-sourceOpen finding ↗