ThreatCluster

Critical OS Command Injection Vulnerability in FortiSandbox Disclosed

First seen 10 Dec 2025, 13:46 UTC CybersecuritynewsCyberpress 38

Article Content

Browse articles
ThreatCluster

A critical OS command injection vulnerability has been identified in Fortinet's FortiSandbox platform, allowing attackers to execute arbitrary code and potentially take control of affected systems. The vulnerability, tracked as CVE-2025-53949, was officially published on December 9, 2025, prompting Fortinet to issue a security update to mitigate the risk.