Attention Fortinet FortiSandbox Users! CISA Warns of Critical Vulnerabilities Actively Exploited in Real-World Cyberattacks

Imported from official source

Announcement

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two dangerous vulnerabilities affecting the Fortinet FortiSandbox platform to its Known Exploited Vulnerabilities (KEV) Catalog. This indicates that these vulnerabilities are being actively exploited by cybercriminals in real-world attacks.

According to security experts, if successfully exploited, these vulnerabilities could allow attackers to execute arbitrary operating system commands remotely without authentication, bypass security mechanisms, and gain complete control over affected systems.

The actively exploited vulnerabilities are:

Both vulnerabilities are classified as OS Command Injection (CWE-78) flaws. They occur because user-supplied input is not properly validated before being passed to operating system commands.

As a result, an attacker can send specially crafted HTTP requests to execute malicious commands on the target system.

This vulnerability specifically affects Fortinet FortiSandbox.

By sending specially crafted HTTP requests, an attacker can:

  • Exploit the system without authentication;
  • Execute the attack without administrator privileges;
  • and execute arbitrary commands at the operating system level.

    This could ultimately allow an attacker to gain complete control over the server.

    The second vulnerability has a broader impact and affects:

    Like the first vulnerability, it can be exploited remotely using specially crafted HTTP requests, allowing attackers to execute arbitrary operating system commands.

    Why Are These Vulnerabilities Dangerous?

    FortiSandbox is widely used in enterprise environments to analyze the following within an isolated sandbox environment:

    It is also commonly integrated with other Fortinet security solutions, including:

    Because of these integrations, compromising a FortiSandbox system could jeopardize not only a single server but an organization’s entire cybersecurity infrastructure.

    According to security experts, attackers exploiting these vulnerabilities could:

    This is an extract. The publication continues at the source.

    Read the original at the source: https://uzcert.uz/en/attention-fortinet-fortisandbox-users-cisa-warns-of-critical-vulnerabilities-actively-exploited-in-real-world-cyberattacks/

    Officially imported this from UZCERT’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    UZCERT — imported from official source
    Official source
    https://uzcert.uz/en/feed/ RSS
    Imported
    October 03, 2026 20:40
    Versions
    1 recorded
    Identity
    https://uzcert.uz/?p=39222

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.