🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Fortinet FortiSandbox Unauthenticated RCE (CVE-2026-25089) — CISA KEV, Patch by July 19
Critical🔴 KEV ALERTConfirmed
DateJuly 16, 2026
CVECVE-2026-25089
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
CISA has added CVE-2026-25089, an unauthenticated OS command injection flaw in Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS, to the Known Exploited Vulnerabilities catalog. An unauthenticated attacker can execute arbitrary commands via crafted HTTP requests, meaning no credentials are required to own the device. CISA does not add vulnerabilities to the KEV catalog as a precaution, so treat active exploitation as a confirmed fact right now.
⚠️Why It Matters for MSSPs
FortiSandbox sits inside security stacks as a trusted inspection layer, and if your MSSP or any of your clients runs it, an attacker already has a path to execute commands on that device without logging in first. Your direct exposure is real if FortiSandbox is part of your own tooling or your shared security infrastructure, and your advisory obligation is equally real because any client running this product is exposed and they have not been told yet. Silence on a KEV-listed, unauthenticated RCE is a contract and retention problem waiting to happen.
✅Recommended Action
In the next 24 hours, audit every instance of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS across your own stack and every client environment you manage, and document which are internet-exposed. Push the Fortinet vendor patch immediately for any exposed instance, and if a patch cannot be applied before end of business today, take that instance offline or block external access at the perimeter until it can be patched. Send a direct client notification today, not this week, so your clients hear about this from you before they read it elsewhere.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.