CISA KEV 警告 26/07/16:Fortinet FortiSandbox の脆弱性 CVE-2026-39808/25089 を KEV に登録

CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands

2026/07/17 gbhackers — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Fortinet の FortiSandbox に存在する 2 件の深刻な脆弱性 CVE-2026-39808CVE-2026-25089 を、Known Exploited Vulnerabilities (KEV) カタログに追加した。これらの脆弱性は、OS コマンド・インジェクションの脆弱性 (CWE-78) に起因し、影響を受けるシステム上での不正なコマンド実行に悪用されている。影響が及ぶ製品の範囲は、FortiSandbox Cloud/FortiSandbox PaaS などの FortiSandbox の導入環境となる。

Continue reading “CISA KEV 警告 26/07/16:Fortinet FortiSandbox の脆弱性 CVE-2026-39808/25089 を KEV に登録”

FortiSandbox の脆弱性 CVE-2026-39813/39808/25089:実環境での悪用を観測

Hackers Exploit Critical Fortinet FortiSandbox Flaws in Active Attacks

2026/06/16 gbhackers — Fortinet FortiSandbox アプライアンスに存在する、複数の深刻な脆弱性を標的とする積極的な悪用の試みを、セキュリティ研究者たちが報告した。それにより、エンタープライズ・セキュリティ・インフラに対する侵害の懸念が高まっている。Defused Cyber が共有した脅威インテリジェンスによると、新たに開示された CVE-2026-39813/CVE-2026-39808/CVE-2026-25089 などの脆弱性が、過去 24 時間以内に悪用され始めている。

Continue reading “FortiSandbox の脆弱性 CVE-2026-39813/39808/25089:実環境での悪用を観測”

Fortinet FortiSandbox の脆弱性 CVE-2026-25089 が FIX:OS コマンド・インジェクション

Fortinet FortiSandbox Vulnerability Lets Attackers Execute Unauthorized Commands

2026/06/10 gbhackers — Fortinet が公表したのは、FortiSandbox 製品における深刻な脆弱性に関する情報である。この脆弱性 CVE-2026-25089 を悪用する未認証の攻撃者は、不正なコマンド実行の可能性を手にするため、マルウェア分析のためにサンドボックスを利用する企業にとって重大な懸念となる。

Continue reading “Fortinet FortiSandbox の脆弱性 CVE-2026-25089 が FIX:OS コマンド・インジェクション”