CuraSec

Act archived

CVE-2026-25089: FortiSandbox unauthenticated RCE added to CISA KEV

2026-07-21 12:43 UTC · HN (cve) · read the source ↗ #fortinet#command-injection#cisa-kev
  • Engineer — Act: FortiSandbox is actively exploited per CISA KEV listing with a public PoC on GitHub; patch to the fixed version immediately and check for signs of compromise on any internet-facing FortiSandbox appliances.
  • SOC/IR — Act: KEV listing plus public PoC means exploitation is likely underway; hunt for anomalous outbound connections or new processes spawned from FortiSandbox hosts since the PoC publication date, and check edge appliance logs for unauthenticated command-injection attempts.
  • Leader — Plan: KEV-listed Fortinet RCE warrants confirming whether FortiSandbox is in the environment and requesting patch status from the infrastructure team; brief on remediation timeline if deployed, given the active exploitation signal.
  • Signals: CVE-2026-25089 — CISA KEV: listed, EPSS 0.36, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.