Fortinet security advisory (AV26-568) – Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial number: AV26-568 Date: June 9, 2026 Updated: July 16, 2026 On June 9, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following: FortiSandbox 5.0 – versions 5.0.0 to 5.0.5 FortiSandbox 4.4 – versions 4.4.0 to 4.4.8 FortiSandbox Cloud 5.0 – versions 5.0.4 to 5.0.5 FortiSandbox PaaS 5.0 – versions 5.0.4 through 5.0.5 Update 1 On July 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-25089 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Second-Order OS Command Injection via JSON Input on start vnc feature Fortinet PSIRT Advisories CISA KEV: CVE-2026-25089
CSIRTS triage
- What
- A second-order OS command injection vulnerability exists via JSON input on the start VNC feature.
- Who is affected
- Users of FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8, and FortiSandbox Cloud versions 5.0.4 to 5.0.5.
- Urgency
- Remediation is critical as the vulnerability has been added to the KEV Database due to active exploitation.
- Action
- Update to the latest versions as specified in the advisory.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiSandbox
Get an email when a new FortiSandbox advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-568
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-25089Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-25089 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploitedFortinet security advisory (AV26-351) – Update 2cccs
- highexploitedCISA Adds Three Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerabilitycisa-kev
- unknownSecond-Order OS Command Injection via JSON Input on start vnc featurefortinet
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30