An Improper Neutralization of Special Elements used in an OS Command ('OS command injection') vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
FortiSanbox PaaS 5.0 is not impacted by the issue and hence customers do not need to perform any action.
2026-04-14: Initial publication
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
