Fortinet FortiSandbox OS Command Injection Vulnerability
- Severity
- Critical9.8CVSS 3.1, Critical
- Known exploited
- Known exploitedFederal remediation due date: 19 Jul 2026
- Exploit prediction
- 47%
- Published
- 14 Apr 2026Updated 17 Jul 2026 · Last verified 30 Sept 2026
Known remediation
Fixed releases per branch, as the vendor states them. Patcharo never infers a fix.
Fortinet FortiSandbox
Vendor advisory- 4.4Fixed after 4.4.8
Workaround / Vendor remediation
Vendor remediation · FortiSandbox
Upgrade to FortiSandbox version 4.4.9 or above Upgrade to FortiSandbox PaaS version 5.0.2 or above
Description
Title, description and vendor guidance are quoted from the source records.
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Weakness: CWE-78
Known exploited
Added to CISA KEV on 16 Jul 2026
Federal remediation due date: 19 Jul 2026
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Exploit prediction
47% probability of exploitation in the next 30 days (percentile 99%).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the source states, per branch
Versions matched by Patcharo
Fortinet FortiSandboxSource: Fortinet (CVE record)
| Branch | Affected | Fixed in |
|---|---|---|
| 4.4 | 4.4.0 – 4.4.8 | Fixed after 4.4.8 |
Versions not listed are stated unaffected by the vendor.
Affected products
- Fortinet FortiSandbox PaaS · 23.4.4374, 23.4.4350, 23.3.4329, 23.1.4245, 22.2.4151, 22.2.4134, 22.1.4113, 21.4.4072, 21.3.4055
References
Provenance
Every fact on this page comes from the sources below. Nothing is written by an AI.
- Fortinet (CVE record)
- Fortinet (CVE record) · 30 Sept 2026 at 00:17 UTC · Parser patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 30 Sept 2026 at 00:17 UTC · Parser patcharo-kev/1.0.0
- NVD
- NVD · 28 Sept 2026 at 07:02 UTC · Parser patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 30 Sept 2026 at 00:17 UTC · Parser patcharo-epss/1.0.0
Last verified: 30 Sept 2026 at 00:17 UTC