CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV

·Hacker News··

Fortinet FortiSandbox contains a critical OS command injection vulnerability (CVSS 9.8) in the web UI allowing unauthenticated remote code execution via crafted HTTP requests. Third FortiSandbox CVE exploited in 2026. CISA KEV listed. Find exposed instances with RECON.

Read full article →

Related Articles

Omarchy: Any User Process Can Escalate to Root
trap0xcc · Hacker News · 10h ago
METR and Redwood Offer Holy %^ Postmortem of the HuggingFace Hack
catbird · Hacker News · 12h ago
Bug Blindness
davidmckenna · Hacker News · 1d ago
The world may have less time than it thinks on climate change
andsoitis · Hacker News · 7h ago
Haiku R1/beta6 has been released
metrofun · Hacker News · 10h ago