other—candidate
Candidate: CVE-2026-25089
Auto-proposed from 2 linked articles (CVE-2026-25089).
Evidence
- evidenceIvanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities · thehackernews
- evidenceAttackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week · thehackernews
Objective core
- factFortinet released a security update for FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS.
- factCVE-2026-25089 is a command injection vulnerability in FortiSandbox with a CVSS score of 9.1.
- factIvanti and SAP released security updates for multiple critical vulnerabilities.
- factThe vulnerabilities could result in arbitrary code execution and information disclosure.
- factDefused Cyber reported exploitation of three Fortinet FortiSandbox vulnerabilities.
- factThese three vulnerabilities are being exploited in the wild as of the last 24 hours.
- factCVE-2026-39813 has a CVSS score of 9.1.
- factCVE-2026-39813 is a path traversal vulnerability in the FortiSandbox JRPC API.
json · rss · all events