CISA has added two critical Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, warning that attackers are actively exploiting the flaws in real-world attacks. The vulnerabilities, identified as CVE-2026-39808 and CVE-2026-25089, allow unauthenticated attackers to execute unauthorized operating system commands through specially crafted HTTP requests. Both issues are classified as OS command injection vulnerabilities (CWE-78), which occur when an application fails to properly sanitize user-controlled input before passing it to an operating system command interpreter. Successful exploitation can enable attackers to run arbitrary commands on vulnerable devices without needing valid credentials....
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!