An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
2026-06-09: Initial publication
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
