Attention Fortinet FortiSandbox Users! CISA Warns of Critical Vulnerabilities Actively Exploited in Real-World Cyberattacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two dangerous vulnerabilities affecting the Fortinet FortiSandbox platform to its Known Exploited Vulnerabilities (KEV) Catalog. This indicates that these vulnerabilities are being actively exploited by cybercriminals in real-world attacks.
According to security experts, if successfully exploited, these vulnerabilities could allow attackers to execute arbitrary operating system commands remotely without authentication, bypass security mechanisms, and gain complete control over affected systems.
The actively exploited vulnerabilities are:
Both vulnerabilities are classified as OS Command Injection (CWE-78) flaws. They occur because user-supplied input is not properly validated before being passed to operating system commands.
As a result, an attacker can send specially crafted HTTP requests to execute malicious commands on the target system.
This vulnerability specifically affects Fortinet FortiSandbox.
By sending specially crafted HTTP requests, an attacker can:
and execute arbitrary commands at the operating system level.
This could ultimately allow an attacker to gain complete control over the server.
The second vulnerability has a broader impact and affects:
Like the first vulnerability, it can be exploited remotely using specially crafted HTTP requests, allowing attackers to execute arbitrary operating system commands.
Why Are These Vulnerabilities Dangerous?
FortiSandbox is widely used in enterprise environments to analyze the following within an isolated sandbox environment:
It is also commonly integrated with other Fortinet security solutions, including:
Because of these integrations, compromising a FortiSandbox system could jeopardize not only a single server but an organization’s entire cybersecurity infrastructure.
According to security experts, attackers exploiting these vulnerabilities could:
This is an extract. The publication continues at the source.
Read the original at the source: https://uzcert.uz/en/attention-fortinet-fortisandbox-users-cisa-warns-of-critical-vulnerabilities-actively-exploited-in-real-world-cyberattacks/
Officially imported this from UZCERT’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- UZCERT — imported from official source
- Official source
- https://uzcert.uz/en/feed/ RSS
- Imported
- October 03, 2026 20:40
- Versions
- 1 recorded
- Identity
https://uzcert.uz/?p=39222