P.01CVE-2026-25089 and CVE-2026-39808: The FortiSandbox Chain That Reaches Unauthenticated Root
CISA added two FortiSandbox command injection bugs to its Known Exploited Vulnerabilities catalog on July 16. Chained with a third flaw, they let an attacker with no credentials at all reach root. Here's how the chain works and what to patch.























