惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cloudbric
Cloudbric
A
About on SuperTechFans
D
Docker
P
Proofpoint News Feed
G
Google Developers Blog
T
The Blog of Author Tim Ferriss
B
Blog RSS Feed
The Last Watchdog
The Last Watchdog
S
Security @ Cisco Blogs
C
CXSECURITY Database RSS Feed - CXSecurity.com
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
WordPress大学
WordPress大学
L
LangChain Blog
Cyberwarzone
Cyberwarzone
S
Security Archives - TechRepublic
Engineering at Meta
Engineering at Meta
E
Exploit-DB.com RSS Feed
Apple Machine Learning Research
Apple Machine Learning Research
Recent Announcements
Recent Announcements
N
News and Events Feed by Topic
阮一峰的网络日志
阮一峰的网络日志
S
Security Affairs
Project Zero
Project Zero
V
V2EX - 技术
N
News and Events Feed by Topic
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
C
Cisco Blogs
Forbes - Security
Forbes - Security
云风的 BLOG
云风的 BLOG
H
Heimdal Security Blog
T
Threatpost
C
Check Point Blog
小众软件
小众软件
博客园 - 【当耐特】
博客园 - 三生石上(FineUI控件)
S
Secure Thoughts
罗磊的独立博客
S
Schneier on Security
N
Netflix TechBlog - Medium
T
Tailwind CSS Blog
T
Threat Research - Cisco Blogs
C
Cybersecurity and Infrastructure Security Agency CISA
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Microsoft Azure Blog
Microsoft Azure Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
S
Securelist
Recorded Future
Recorded Future
AWS News Blog
AWS News Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More

Arctic Wolf

Home-Field Disadvantage: AiTM, QR-Code Phishing, and Infostealers at the 2026 FIFA World Cup arcticwolf.com arcticwolf.com Celebrating Arctic Wolf’s 2026 Partner of the Year Winners at Global Partner Kickoff Die Auswahl Einer Vulnerability Management-Lösung The Hidden Economics of the Agentic SOC The Hidden Economics of the Agentic SOC | Arctic Wolf Security Operations in Maschinen-Geschwindigkeit Aurora Mobile Threat Defense — Addressing Your Highest‑Trusted, Least Protected Endpoints - Arctic Wolf Aurora Mobile Threat Defense — Addressing Your Highest‑Trusted, Least Protected Endpoints - Arctic Wolf How Aurora Managed Endpoint Defense Combines Experts and Technology to Simplify Security Aurora Endpoint Sicherheitsportfolioa | Arctic Wolf From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services arcticwolf.com arcticwolf.com Arctic Wolf Product Updates: May 2026 arcticwolf.com Arctic Wolf Product Updates: May 2026 FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch - Arctic Wolf FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch What’s New What’s Next with Arctic Wolf: May 2026 Update Cybersecurity Trends in the Age of AI arcticwolf.com Arctic Wolf、AI搭載のモバイル脅威防御ソリューションを発表、 増加するモバイル端末を標的としたサイバー攻撃から組織を保護 How Arctic Wolf Aurora Mobile Threat Defense Protects the Mobile Attack Surface How AI Is Transforming Detection Engineering 「Aurora Mobile Threat Defense」の提供が開始されました Accelerating Cloud Security Outcomes Together: Why Arctic Wolf and Wiz are Redefining What’s Possible - Arctic Wolf InfoSecurity Europe 2026 OpenAI Daybreak and the Future of Secure Software Development - Arctic Wolf OpenAI Daybreak and the Future of Secure Software Development Turning Security Telemetry Into Actionable Insights | Arctic Wolf Detecting Identity Attacks at Scale with Herd Immunity Detecting Identity Attacks at Scale with Herd Immunity | Arctic Wolf arcticwolf.com arcticwolf.com PowerShell Security | Arctic Wolf How to Gain Visibility and Reduce Exposure with Aurora Attack Surface Management arcticwolf.com Mini Shai-Hulud: Supply Chain Malware Attack arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com Arctic Wolf Introduces the Next Era of Exposure Management to Help Organizations Outpace AI-Accelerated Vulnerability Discovery Arctic Wolf Launches AI-Powered Mobile Threat Defense to Protect Organizations Against Growing Mobile-based Cyber Threats Aurora Mobile Threat Defense is Now Available Turning Visibility Into Action: Introducing Aurora Exposure Management Protecting Against IOT Security Risks | Arctic Wolf CVE-2026-0300 — Critical Buffer Overflow in PAN-OS User-ID Authentication Portal IoT Security Risks | Arctic Wolf arcticwolf.com Should Your Organization Rely on XDR? | Arctic Wolf 止まらないランサムウェア被害 - Qilinの事案から読み解く、検知、対応と経営判断 arcticwolf.com Why Cybersecurity Still Matters Even If AI Improves Secure Development | Arctic Wolf Aurora® Attack Surface Management For Healthcare arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com CVE-2026-41940: Critical Exploited Authentication Bypass Vulnerability in cPanel & WHM Why Vulnerability Prioritization Requires More Than a Score | Arctic Wolf Token Bingo: Don’t Let Your Code be the Winner EFM Philadelphia IT Symposium MN Bankers Operations and Technology Conference SecureMiami 2025 Cyber Identity Summit – Ottawa MISA Exec Summit – Victoria Arkansas IT Symposium – efmEvents Cybersecurity Summit – Boston Houston Technology Summit – elevateIT Nevada Public Sector Cybersecurity Summit SecureWorld Philadelphia Nick Schneider of Arctic Wolf named Entrepreneur Of The Year® 2026 Heartland finalist by EY US arcticwolf.com arcticwolf.com Introducing Decipio: A Community Tool to Catch Credential Theft in the Act with Defense First AI Arctic Wolf Introduces Decipio, a Community Tool to Catch Credential Theft with Defense‑First AI Proxy Server Endpoint Endpoint Detection and Response AIマルウェアの急増:その挙動、攻撃主体の特定、防御体制の備え arcticwolf.com arcticwolf.com Project Glasswing Marks a Turning Point for Cybersecurity Frontier AI Models Mark a Turning Point for Cybersecurity arcticwolf.com arcticwolf.com Building Cyber Resilience with Arctic Wolf: A Practical Approach for Security Leaders Arctic Wolf、東映デジタルラボ株式会社を Aurora Managed Endpoint Defenseで保護 Arctic Wolf Named a 2026 Gartner® Peer Insights™ Customers’ Choice for Managed Detection and Response arcticwolf.com
CVE-2026-25089 | Arctic Wolf
Arctic Wolf Labs · 2026-06-16 · via Arctic Wolf

Security Bulletin text on the screen with a wolf in the background

Security Bulletin text on the screen with a wolf in the background

CVE-2026-25089: Fortinet FortiSandbox Critical OS Command Injection Vulnerability Immediate Action Required

CVE-2026-25089 is a critical OS command injection vulnerability discovered in Fortinet FortiSandbox versions 4.4.0–4.4.8, 5.0.0–5.0.5, and corresponding Cloud and Platform as a Service deployments.

Security Bulletin text on the screen with a wolf in the background

Threat Summary

CVE-2026-25089 is a critical OS command injection (CWE-78) vulnerability discovered in Fortinet FortiSandbox versions 4.4.0–4.4.8, 5.0.0–5.0.5, and corresponding Cloud and Platform as a Service (PaaS) deployments (5.0.4–5.0.5). The flaw allows unauthenticated, remote attackers to execute arbitrary system commands by sending specially crafted HTTP requests, leveraging improper input sanitization—primarily in the ‘start VNC’ web UI feature. This leads to remote code execution (RCE), full system compromise, access to sensitive sandboxed data, potential network pivoting, and attacker persistence.

The vulnerability was reported by Fortinet’s PSIRT and publicly disclosed in advisory FG-IR-26-141 on June 9, 2026. Fortinet released patches concurrently, and the issue was also published by NIST’s NVD and various regional CSIRTs. As of mid-June 2026, no active exploitation has been confirmed; however, the low complexity and unauthenticated nature make rapid weaponization likely, especially for any FortiSandbox appliances exposed to public or semi-public networks.

Though FortiSandbox has a limited enterprise footprint (market share ≈0.06%), its deployments are typically in high-value sectors—such as financial services, large enterprises, and critical infrastructure—which magnifies the potential impact of compromise. Organizations that rely on these sandbox solutions for file and malware detonation should act with utmost urgency, as successful exploitation directly undermines inspection, containment, and indirectly, broader enterprise security programs.

Recommendations

PRIORITY: Patch and Restrict Access Immediately

  • Identify Affected Systems
    • Inventory all FortiSandbox instances (on-premises, Cloud, and PaaS) using affected versions ( 4.4.0–4.4.8, 5.0.0–5.0.5, Cloud/PaaS 5.0.4–5.0.5).
  • Apply Vendor Patches Without Delay
    • Upgrade FortiSandbox on-premises to 0.6 or later; 4.4.0–4.4.8 to 4.4.9 or later.
    • For Cloud and PaaS: upgrade to 0.6 or higher.
    • Confirm patching via product info or version check post-upgrade.
  • Restrict Web UI Exposure
    • Immediately remove public or external network access to the administrative web interface.
    • Enforce access via trusted internal networks, VPN, or jump hosts.
  • Deploy Temporary Compensating Controls
    • Use Web Application Firewall (WAF) rules to block malicious HTTP requests (e.g., targeting ‘start VNC’ endpoint, suspicious parameter patterns) until patches are fully applied.
  • Assess Previous Verdicts/Scans
    • If compromise is suspected or verified, reanalyze previously detonated files and review verdict history for possible evasion or post-infection activity.
  • Maintain Security Network Segmentation
    • Ensure minimal trust and strictly limit network paths from sandboxes to critical enterprise infrastructure as a long-term best practice.
  • Continue Security Intelligence Monitoring
    • Monitor for future PoC releases or reports of active exploitation.
    • Subscribe to Fortinet PSIRT, NIST NVD, and your regional CERT advisories for updates and IOCs.

Temporary Workarounds

If immediate patching is not possible:

  • Network Isolation: Place affected FortiSandbox systems behind strict internal network barriers; enforce admin access via VPN and disallow direct internet exposure.
  • Web Application Firewall (WAF): Use application layer filtering to block or sanitize HTTP requests with uncommon parameters or payloads, especially those using shell metacharacters in JSON to the ‘start VNC’ function.
  • Enhanced Monitoring: Enable and inspect verbose logging on web server and system processes to detect suspicious access patterns or command execution attempts.

Limitations: These workarounds reduce exposure but do not remove the vulnerability. Only full patching guarantees remediation. Be advised that internal threats or already compromised systems may still be at risk until patched.

References

Share this post:

What to read next

Arctic Wolf Blog Featured Image

5 min read

CVE-2026-0300 — Critical Buffer Overflow in PAN-OS User-ID Authentication Portal

May 7, 2026

Arctic Wolf Blog Featured Image

6 min read

Beyond the Bug: Why Cybersecurity Still Matters Even If AI Improves Secure Development

May 1, 2026

Arctic Wolf Blog Featured Image

6 min read

Microsoft Patch Tuesday: April 2026 

April 14, 2026

Arctic Wolf Blog Featured Image

2 min read

CVE-2026-35616: Fortinet Releases Hotfix for Critical Exploited Vulnerability in FortiClient EMS

April 6, 2026