Act
archived
CVE-2026-25089: FortiSandbox unauthenticated RCE added to CISA KEV
- Engineer — Act: FortiSandbox is actively exploited per CISA KEV listing with a public PoC on GitHub; patch to the fixed version immediately and check for signs of compromise on any internet-facing FortiSandbox appliances.
- SOC/IR — Act: KEV listing plus public PoC means exploitation is likely underway; hunt for anomalous outbound connections or new processes spawned from FortiSandbox hosts since the PoC publication date, and check edge appliance logs for unauthenticated command-injection attempts.
- Leader — Plan: KEV-listed Fortinet RCE warrants confirming whether FortiSandbox is in the environment and requesting patch status from the infrastructure team; brief on remediation timeline if deployed, given the active exploitation signal.
- Signals: CVE-2026-25089 — CISA KEV: listed, EPSS 0.36, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.