Finding
indicator:42314:descriptionWhat happened
CISA KEV describes CVE-2026-25089 as: Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.