CVE-2026-25089
CRITICAL(9.8)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
- EPSS 76% — sehr wahrscheinlich ausgenutzt
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
76.1%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
SecBoard-Einordnung
CVE-2026-25089 betrifft Fortinet FortiSandbox und FortiSandbox Cloud/PaaS und ist eine Schwachstelle vom Typ 'OS Command Injection'. Sie ermöglicht einem nicht authentifizierten Angreifer die Ausführung beliebiger Befehle über speziell gestaltete HTTP-Anfragen. Die erfolgreiche Ausnutzung kann zu einer vollständigen Kompromittierung des betroffenen Systems führen.
Die Schwachstelle wird als kritisch eingestuft, mit einem CVSS-Score von 9.8. Die Exploit-Wahrscheinlichkeit ist mit einem EPSS-Wert von 74% hoch. Besonders besorgniserregend ist, dass diese CVE aktiv ausgenutzt wird und im CISA Known Exploited Vulnerabilities (KEV) Katalog gelistet ist, was eine sofortige Reaktion erfordert.
Security-Teams sollten umgehend prüfen, ob betroffene FortiSandbox-Versionen im Einsatz sind. Eine schnelle Implementierung verfügbarer Patches oder Workarounds ist dringend erforderlich, um das Risiko einer Kompromittierung zu minimieren. Zusätzlich sollte die Überwachung auf ungewöhnliche Aktivitäten auf FortiSandbox-Systemen intensiviert werden.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests