Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Fortinet FortiSandbox
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .7360 99.4 YES
AFFECTED
Product Versions Fixed
FortiSandbox 5.0.0 – —
FortiSandbox Cloud 5.0.4 – —
FortiSandbox PaaS 5.0.4 – —
TIMELINE
Jan 29 Reserved by fortinet
Jul 16 Added to CISA KEV, remediation due 2026-07-19
Jul 16 Published (CNA: fortinet)
Jul 20 DUE DATE PASSED — CVE-2026-25089 (Fortinet FortiSandbox). CISA remediation deadline was July 19, 2026; still in catalog.
Jul 23 ENRICHED — CVE-2026-25089 (Fortinet FortiSandbox). Received CVSS 9.8 and CPE data from NVD.
Description
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
Lifecycle
Complete event history — 5 events, chronological
| Date | Event | Detail |
| January 29, 2026 | Reserved | Reserved by fortinet |
| July 16, 2026 | KEV ADDED | Added to CISA KEV, remediation due 2026-07-19 |
| July 16, 2026 | Published | Published (CNA: fortinet) |
| July 20, 2026 | DUE DATE PASSED | DUE DATE PASSED — CVE-2026-25089 (Fortinet FortiSandbox). CISA remediation deadline was July 19, 2026; still in catalog. |
| July 23, 2026 | ENRICHED | ENRICHED — CVE-2026-25089 (Fortinet FortiSandbox). Received CVSS 9.8 and CPE data from NVD. |
Affected
Affected products and packages — 3 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Fortinet | FortiSandbox | — | 5.0.0 | — |
| Fortinet | FortiSandbox Cloud | — | 5.0.4 | — |
| Fortinet | FortiSandbox PaaS | — | 5.0.4 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-25089 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.