---
schema: 1
kind: vulnerability
title: >
  CVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's
  VNC-launch handler (CVSS 9.8)
headline: >
  CVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's
  VNC-launch handler (CVSS 9.8)
summary: >
  Fortinet patched CVE-2026-25089 (CWE-78, internal reference FG-IR-26-141) on 9 June: the
  FortiSandbox web interface's "start VNC" handler passes attacker-controlled JSON to the
  underlying OS without sanitisation, allowing a remote unauthenticated attacker to achieve
  second-order command injection via a crafted HTTP …
discovered_at: "2026-06-12T05:00:06Z"
updated_at: "2026-06-17T05:14:32Z"
event_date: 2026-06-11
run_id: 2026-06-12-5ab9a319
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - pre-auth
  - rce
  - poc-public
  - patch-available
  - actively-exploited
  - auth-bypass
regions:
  - europe
  - global
sectors:
  - public-sector
  - technology
  - defense
  - healthcare
entities: []
techniques: []
affected_products: []
cves:
  - id: CVE-2026-25089
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
  - id: CVE-2026-39808
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
  - id: CVE-2026-39813
    cvss: "9.1"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
sources:
  - url: "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0189"
    publisher: NCSC-NL NCSC-2026-0189
    role: primary
  - url: "https://ccb.belgium.be/advisories/warning-fortinet-addresses-critical-command-injection-vulnerability-fortisandbox-patch"
    publisher: CCB Belgium
    role: corroborating
  - url: "https://securityaffairs.com/193709/ai/fortinet-warned-as-three-critical-fortisandbox-bugs-come-under-attack.html"
    publisher: "Security Affairs, 2026-06-16"
    role: primary
  - url: "https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/"
    publisher: "Help Net Security, 2026-06-16"
    role: corroborating
closed_sources: []
evidence:
  - quote: "UPDATE (originally covered 2026-06-12): When CVE-2026-25089 was covered on 06-12 it was disclosure-only."
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**Patch FortiSandbox to 5.0.6 / 4.4.9 and confirm the management interface is off the internet (CVE-2026-25089).** A compromised sandbox exposes every file your SOC detonates."
  - "**Patch all three FortiSandbox CVEs and restrict the management interface** (§ 4). CVE-2026-39808/39813 (April patches) and CVE-2026-25089 (06-09 patch) are under simultaneous exploitation; a compromised sandbox suppresses blocking across the FortiGate/FortiMail stack. Watch JRPC/web-UI access logs for unauthenticated external POSTs."
updates:
  - at: "2026-06-17T05:14:32Z"
    run_id: 2026-06-17-e102009c
    type: update
    summary: >
      Three critical FortiSandbox flaws are now under simultaneous active exploitation —
      CVE-2026-39808, CVE-2026-39813 (April patches) and CVE-2026-25089 (patched 2026-06-09,
      previously disclosure-only here on 06-12) were all observed exploited in a 24-hour window;
      FortiSandbox feeds verdicts to the wider FortiGate/FortiMail stack (§ 4).
    fields:
      - actions
      - cves
      - evidence
      - priority
      - sectors
      - sources
      - tags
      - body
    merged_from: 2026-06-17/fortisandbox-three-critical-flaws-now-exploited-simultaneous
migrated_from: briefs/2026-06-12.md
---

Fortinet patched CVE-2026-25089 (CWE-78, internal reference FG-IR-26-141) on 9 June: the FortiSandbox web interface's "start VNC" handler passes attacker-controlled JSON to the underlying OS without sanitisation, allowing a remote unauthenticated attacker to achieve second-order command injection via a crafted HTTP request ([NCSC-NL, 2026-06-11](https://advisories.ncsc.nl/advisory?id=NCSC-2026-0189)). Affected: FortiSandbox 5.0.0–5.0.5 and 4.4.0–4.4.8 (plus corresponding Cloud/PaaS builds); fixed in 5.0.6 and 4.4.9. CCB Belgium urges immediate patching and warns that the public availability of a proof-of-concept exploit increases the likelihood of exploitation ([CCB Belgium, 2026-06-11](https://ccb.belgium.be/advisories/warning-fortinet-addresses-critical-command-injection-vulnerability-fortisandbox-patch)). No in-the-wild exploitation is reported, and the management interface is not meant to be internet-reachable — but with a public PoC available, a compromised FortiSandbox hands an attacker every file your SOC submits for detonation, plus a trusted foothold inside the security stack ([T1190](https://attack.mitre.org/techniques/T1190/)). Discovered internally by Fortinet's product-security team; the FortiGuard PSIRT page was unreachable in this run (.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-35273 | Oracle PeopleSoft PeopleTools 8.61/8.62 (PSEMHUB) | 9.8 | n/a | No | **Yes — zero-day, UNC6240** | Out-of-band alert 2026-06-10 | [Oracle](https://www.oracle.com/security-alerts/alert-cve-2026-35273.html) |
| CVE-2026-49261 | MariaDB Server (Galera `wsrep_notify_cmd`) | 10.0 | n/a | No | No | 11.8.8 / 11.4.12 / 10.11.18 / 10.6.27 | [NCSC-CH](https://security-hub.ncsc.admin.ch/#/posts/12627) |
| CVE-2026-45657 | Windows kernel (TCP/IP) | 9.8 | n/a | No | No | June 2026 cumulative | [MSRC](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45657) |
| CVE-2026-26142 | Nuance PowerScribe | 9.8 | n/a | No | No | June 2026 update | [MSRC](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-26142) |
| CVE-2026-47643 | Azure Stack Edge | 9.8 | n/a | No | No | June 2026 update | [MSRC](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-47643) |
| CVE-2026-48579 | Exchange Online | 9.1 | n/a | No | No | Service-side, no customer action | [MSRC](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-48579) |
| CVE-2026-25089 | Fortinet FortiSandbox | 9.8 | n/a | No | PoC public | 5.0.6 / 4.4.9 | [NCSC-NL](https://advisories.ncsc.nl/advisory?id=NCSC-2026-0189) |

## Update — 2026-06-17T05:14:32Z

When CVE-2026-25089 was covered on 06-12 it was disclosure-only. Threat-intel firm Defused Cyber has now reported active exploitation of three FortiSandbox flaws within a single 24-hour window — CVE-2026-39808 (CVSS 9.8, JRPC OS command injection), CVE-2026-39813 (CVSS 9.1, JRPC path traversal / auth bypass), both with patches available since April 2026, and CVE-2026-25089 (CVSS 9.8, web-UI command injection), patched 2026-06-09 ([Security Affairs, 2026-06-16](https://securityaffairs.com/193709/ai/fortinet-warned-as-three-critical-fortisandbox-bugs-come-under-attack.html)).

FortiSandbox supplies sandboxed file verdicts that FortiGate, FortiMail, FortiProxy and FortiClient consume to make blocking decisions, so a compromised sandbox can suppress detection across the dependent Fortinet stack ([Help Net Security, 2026-06-16](https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/)). The CVE-2026-25089 exploit seen in the wild appears AI-generated and is assessed as faulty, yet still finds traction against unpatched deployments — evidence that exposed, unpatched FortiSandbox interfaces remain. Fortinet has not yet officially confirmed exploitation. Patch all three; until then, restrict management-interface exposure and watch FortiSandbox web-UI/JRPC access logs for unauthenticated external POSTs.
