Hackers Attempt to Exploit Fortinet Sandbox Flaw, Possibly With AI Assistance
Fortinet's FortiSandbox analyzes suspicious files and programs in isolated environments and is deployed across enterprise, cloud and PaaS environments. CVE-2026-25089 is an operating system command-injection vulnerability that can be triggered without authentication through a specially crafted HTTP request and carries a CVSS score of 9.1. Successful exploitation could allow attackers to execute unauthorized commands, threatening corporate networks and malware-analysis defenses.
Threat intelligence firm Defused said on June 15, 2026, that it had observed hackers attempting to exploit CVE-2026-39813, CVE-2026-39808 and CVE-2026-25089 over the previous 24 hours. Fortinet released patches on April 14 and June 9. Defused assessed that the exploit code for CVE-2026-25089 may have been written with AI assistance, but the version seen at the time appeared to contain errors, and there was no evidence of a successful breach.
All Coverage
1 original reportsThe Backstory
The history behind this eventFortinet Patches Critical FortiSandbox Vulnerability
Fortinet's FortiSandbox is a cybersecurity product that isolates suspicious files in a sandbox and uses AI to improve malware detection. It can be deployed on-premises, in the cloud and in PaaS environments. If the defense system itself is compromised, attackers could turn its analysis interface into a channel for executing system commands, threatening the confidentiality, integrity and availability of the host.
Fortinet issued an advisory on June 9, 2026, classifying CVE-2026-25089 as a critical vulnerability with a CVSS v3 score of 9.1. An unauthenticated attacker could inject operating-system commands through a specially crafted HTTP request. Affected versions include on-premises releases 5.0.0–5.0.5 and 4.4.0–4.4.8, as well as Cloud and PaaS releases 5.0.4–5.0.5. Users should upgrade to version 5.0.6, 4.4.9 or later.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.