- Fortinet has released a security update to address vulnerabilities discovered in the FortiOS and FortiSandbox product families.
- CVE-2025-53844 is an out-of-bounds write vulnerability in FortiOS.
- Affected FortiOS versions are 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.11.
- The patched versions are FortiOS 7.6.4 or later, 7.4.9 or later, and 7.2.12 or later.
- CVE-2026-25089 is an OS command injection vulnerability (a vulnerability where operating system commands are executed unintentionally) occurring in FortiSandbox.
- Affected products and versions include FortiSandbox 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, and FortiSandbox PaaS 5.0.4 through 5.0.5.
- The patched versions are FortiSandbox 5.0.6 or later, 4.4.9 or later, FortiSandbox Cloud 5.0.6 or later, and FortiSandbox PaaS 5.0.6 or later.
- The reference site indicates that CVE-2025-53844 is related to out-of-bounds access in the CAPWAP daemon, and CVE-2026-25089 is related to second-order OS command injection via the “start vnc” feature using JSON input.