CVE-2025-52436Patch(fortinet / fortisandbox)

MEDIUMCVSS 9.6 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch fortinet fortisandbox systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to execute commands via crafted requests.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortisandbox

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-02-11); latest day: 1
  • 12 total mentions across 5 days

Affected systems

Vendors
Products
fortisandbox

Deep dive

Activity timeline12 mentions / 5d
01234Mentions · 2026-02-10: 3Mentions · 2026-02-11: 4Mentions · 2026-02-12: 3Mentions · 2026-02-13: 1Mentions · 2026-02-18: 1Active Exploitation · 2026-02-12: 2Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-11: 4Patch / Workaround · 2026-02-12: 2Technical Details · 2026-02-10: 3Technical Details · 2026-02-11: 3Technical Details · 2026-02-12: 1Technical Details · 2026-02-18: 102-1002-1102-1202-1302-18
Signal classification3 categories
Patch
758.3%
Disclosure
433.3%
General
18.3%
Referenced assets34 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-103
Disclosure2Patch1
2026-02-114
Patch4
2026-02-123
General1Patch2
2026-02-131
Disclosure1
2026-02-181
Disclosure1
Full discourse12 posts
  • سايبركاست@cyberscastx
    Patch

    أصدرت @Fortinet تنبيهات لمعالجة ثغرات في منتجاتها مع وجود ثغرتين عاليتي الخطورة تتطلبان تحديثاً عاجلاً، هما: - الثغرة CVE-2025-52436 بتقييم CVSS 7.9. - الثغرة CVE-2026-22153 بتقييم CVSS 7.5. https://t.co/5LqpQ4toOA

    Post summary

    Fortinet has issued alerts for two high‑severity CVEs (CVE‑2025‑52436 and CVE‑2026‑22153) that require urgent patches; CVSS scores are provided, but no exploit or PoC details are disclosed.

    00062854
    6.4K followersView on X
  • Machina Record@MachinaRecord
    Patch

    🔨マイクロソフト、攻撃で悪用されているゼロデイ6件などを修正(CVE-2026-21533、CVE-2026-21525ほか) 🩹Fortinet、深刻度の高いFortiSandboxとFortiOSの脆弱性にパッチ(CVE-2025-52436、CVE-2026-22153) 〜サイバーアラート 2月11~12日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/43837/

    Post summary

    The post announces that Microsoft and Fortinet have released patches for several high‑severity CVEs, noting that some are actively exploited, but it does not provide exploit code or detailed technical vulnerability data.

    11010208
    1.2K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    FortiSandbox の XSS 脆弱性 CVE-2025-52436 が FIX:マルウェア解析環境でのサンドボックス回避 https://iototsecnews.jp/2026/02/10/fortisandbox-xss-vulnerability-let-attackers-run-arbitrary-commands/ この問題の原因は、管理画面 (GUI) において、Web ページを生成する際の入力値に対する無害化 (サニタイズ) が不十分であったことにあります。具体的には、反射型クロスサイト・スクリプティング (XSS) という欠陥が存在し、細工したリクエストを送信する攻撃者に対して、管理者のブラウザ上での悪意の JavaScript 実行を許してしまいます。ご利用のチームは、ご注意ください。 #CVE202552436 #Fortinet #FortiSandbox #Vulnerability

    Post summary

    The post announces a reflected XSS vulnerability (CVE‑2025‑52436) in FortiSandbox’s GUI, describes its technical nature, but does not provide a PoC, exploit code, or explicit patch details.

    01000144
    484 followersView on X
  • Francesc Rovirosa@fr0viros4
    General

    Fortinet ha reportat la existència d'una vulnerabilitat "Alta/Greu". No importa quan llegeixis això. https://nvd.nist.gov/vuln/detail/CVE-2025-52436 https://fortiguard.fortinet.com/psirt/FG-IR-25-093

    Post summary

    Fortinet reports a high‑severity vulnerability (CVE‑2025‑52436), but no details on exploitation, patches, or technical specifics are provided.

    0001061
    524 followersView on X
  • Machina Record@MachinaRecord
    Patch

    【リンク集:2月10日〜12日のセキュリティ関連ニュース/記事】 <脆弱性> ・Windows 11のメモ帳に脆弱性、Markdownリンク経由でファイルがサイレント実行される(CVE-2026-20841) https://www.bleepingcomputer.com/news/microsoft/windows-11-notepad-flaw-let-files-execute-silently-via-markdown-links/ ・マイクロソフトが2026年2月の月例パッチをリリース、ゼロデイ6件含む58件の脆弱性を修正(CVE-2026-21510、CVE-2026-21513他) https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2026-patch-tuesday-fixes-6-zero-days-58-flaws/ ・SAPが重大な脆弱性を複数修正 CRMやS/4HANA、NetWeaverに存在(CVE-2026-0488、CVE-2026-0509他) https://www.securityweek.com/sap-patches-critical-crm-s-4hana-netweaver-vulnerabilities/ ・米CISA、Microsoft OfficeとMicrosoft Windowsの脆弱性をKEVカタログに追加(CVE-2026-21510、CVE-2026-21513他) https://securityaffairs.com/187855/security/u-s-cisa-adds-microsoft-office-and-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog.html ・ICS月例パッチ:シーメンス、シュナイダーエレクトリック、アヴィバ、フエニックス・コンタクトが脆弱性を修正 https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-addressed-by-siemens-schneider-aveva-phoenix-contact/ ・GoogleとIntelのセキュリティ監査でTDXに深刻な脆弱性が見つかる 完全な侵害を許す恐れ(CVE-2025-32007、CVE-2025-27940他) https://www.securityweek.com/google-intel-security-audit-reveals-severe-tdx-vulnerability-allowing-full-compromise/ ・Fortinet、深刻度の高い脆弱性を修正(CVE-2025-52436、CVE-2026-22153他) https://www.securityweek.com/fortinet-patches-high-severity-vulnerabilities/ <マルウェア・その他脅威> ・北朝鮮のハッカーグループ、新たなmacOSマルウェアで暗号資産窃取を目論む https://www.bleepingcomputer.com/news/security/north-korean-hackers-use-new-macos-malware-in-crypto-theft-attacks/ ・新たなLinuxボットネットのSSHStalker、C2通信に旧式のIRCを使用 https://www.bleepingcomputer.com/news/security/new-linux-botnet-sshstalker-uses-old-school-irc-for-c2-comms/ ・GoogleカレンダーのAIコネクタがマルウェアを起動する恐れ 複数の研究者が指摘 https://www.theregister.com/2026/02/11/claude_desktop_extensions_prompt_injection/ ・モバイル端末へのフルアクセスを可能にするスパイウェア「ZeroDayRAT」 https://securityaffairs.com/187820/malware/zerodayrat-spyware-grants-attackers-total-access-to-mobile-devices.html ・CastleLoaderマルウェアを使ったキャンペーンでLummaStealer感染が急増 https://www.bleepingcomputer.com/news/security/lummastealer-infections-surge-after-castleloader-malware-campaigns/ <ランサムウェア> ・Crazyランサムウェアグループ、従業員監視ツールを攻撃に悪用 https://www.bleepingcomputer.com/news/security/crazy-ransomware-gang-abuses-employee-monitoring-tool-in-attacks/ ・「Reynolds」ランサムウェア、ペイロードにBYOVD用ドライバを埋め込む https://www.darkreading.com/threat-intelligence/black-basta-bundles-byovd-ransomware-payload <データ侵害/サイバー犯罪> ・Conduentのデータ侵害でボルボ・グループに被害、約17,000人分の従業員データが流出 https://www.securityweek.com/conduent-breach-hits-volvo-group-nearly-17000-employees-data-exposed/ ・米ジョージア州の医療関連企業でデータ侵害、62万人以上に影響 https://therecord.media/georgia-healthcare-company-data-breach-impacts-620000 <AI関連> ・Amazon、新たなマーケットプレイスの立ち上げを示唆 メディアサイトがAI企業へコンテンツを販売できる場に https://techcrunch.com/2026/02/10/amazon-may-launch-a-marketplace-where-media-sites-can-sell-their-content-to-ai-companies/ ・中国最大のハッキング大会「天府杯」が公安部主導で復活 AI隆盛のさなかに https://www.nattothoughts.com/p/the-tianfu-cup-returns-under-mps ・AI生成の似顔絵をソーシャルメディアに投稿するリスク、情報セキュリティ関係者が警告 https://www.theregister.com/2026/02/11/ai_caricatures_social_media_bad_security/ <サイバー戦/APT/国家型アクター/地政学関連> ・シンガポールの大手通信企業が中国系APTの標的に ルートキットとゼロデイが悪用される https://www.securityweek.com/singapore-rootkits-zero-day-used-in-chinese-attack-on-major-telecom-firms/ ・APT36とSideCopy、インドの複数組織にクロスプラットフォームRATキャンペーンを展開 https://thehackernews.com/2026/02/apt36-and-sidecopy-launch-cross.html <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・監視ツールメーカー元CEOが「数百万台のコンピューターとデバイス」にアクセス可能なエクスプロイトを露ブローカーに売却 米司法省が公訴事実と認める https://techcrunch.com/2026/02/11/doj-says-trenchant-boss-sold-exploits-to-russian-broker-capable-of-accessing-millions-of-computers-and-devices/ ・オランダ警察、MFAパスコード取得ツール「JokerOTP」の販売者を逮捕 https://www.bleepingcomputer.com/news/security/police-arrest-seller-of-jokerotp-mfa-passcode-capturing-tool/ <プライバシー> ・Google、学生ジャーナリストの個人情報と金銭関連情報をICEに提供か https://techcrunch.com/2026/02/10/google-sent-personal-and-financial-information-of-student-journalist-to-ice/ <政府/政策> ・ロシア政府がTelegramの通信速度を制限 独自のメッセージングアプリを推奨する動きに関連か https://therecord.media/russia-throttles-telegram-pushes-its-own-messaging-app

    Post summary

    The text aggregates recent CVE disclosures and emphasizes vendor patch releases while noting that some vulnerabilities are actively exploited, as highlighted by CISA.

    00010243
    1.2K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Fortinet ❗ CVE-2026-22153 ❗ CVE-2025-52436 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-fortinet-7/ https://t.co/AGcsLdJu8O

    Post summary

    The post lists two CVE identifiers for Fortinet products and directs readers to a link for more information, indicating a vulnerability disclosure announcement.

    00000143
    6.6K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Fortinet discloses high-severity XSS vulnerability (CVE-2025-52436) in FortiSandbox, allowing unauthenticated command execution. Immediate patching recommended. Link: https://thedailytechfeed.com/critical-xss-flaw-in-fortisandbox-allows-unauthenticated-command-execution-users-urged-to-patch-immediately/ #Cybersecurity #Vulnerability #Fortinet #Security #XSS #Exploitation #Patch #Software #Threat #Malware #Network #Hacking #Update #Protection #CVE #Risk #Alert #System #Breach #Defend

    Post summary

    Fortinet has disclosed CVE-2025-52436, a high‑severity XSS flaw in FortiSandbox that enables unauthenticated command execution, and urges users to apply the patch immediately.

    0000059
    234 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Fortinet Patches High-Severity Bugs Enabling Unauth Command Execution + LDAP Auth Bypass Fortinet released fixes for multiple product flaws, including a FortiSandbox XSS (CVE-2025-52436) that can lead to unauthenticated command execution and a FortiOS LDAP authentication bypass (CVE-2026-22153) under certain Agentless VPN/FSSO configurations. Treat this as urgent perimeter hygiene for Fortinet-heavy estates because the affected components sit on high-trust boundary paths (sandboxing, VPN/SSO auth). 🎯 Target: Global/Enterprise (Fortinet FortiOS/FortiGate/FortiSandbox users) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/fortinet-patches-high-severity-vulnerabilities/

    Post summary

    Fortinet has issued patches for CVE‑2025‑52436 (XSS leading to unauthenticated command execution) and CVE‑2026‑22153 (LDAP authentication bypass), emphasizing the need for urgent remediation.

    0000051
    191 followersView on X
  • transilienceai@transilienceai
    Patch

    🚨 FortiSandbox [High] Feb 11, 2026 Comprehensive security advisory on recent vulnerabilities, risk impacts, and mitigation guidance for FortiSandbox, including details of CVE-2025-52436 published within the last 10 days. Checkout our Threat Intelligence Platform:... https://t.co/jmWNWVhJvS

    Post summary

    FortiSandbox issued a security advisory on Feb 11, 2026 with mitigation guidance for CVE-2025-52436, but the post lacks PoC, exploit details, or technical specifics.

    0000054
    315 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-52436: HIGH] Fortinet FortiSandbox versions 5.0.0 to 5.0.1, 4.4.0 to 4.4.7, 4.2, and 4.0 are vulnerable to a 'Cross-site Scripting' flaw (CWE-79), enabling remote attackers to execute commands.#cve,CVE-2025-52436,#cybersecurity https://cvefind.com/CVE-2025-52436

    Post summary

    Fortinet FortiSandbox versions 5.0.0‑5.0.1, 4.4.0‑4.4.7, 4.2, and 4.0 are vulnerable to a high‑severity XSS flaw that can lead to remote command execution.

    0000053
    583 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 FortiSandbox GUI XSS Bug Enables Unauth Command Execution (CVE-2025-52436) Fortinet disclosed a high-severity reflected XSS in FortiSandbox’s GUI (CVE-2025-52436, CVSS 7.9) where crafted requests can inject script that, once an admin views the page, can lead to arbitrary command execution. Patch affected FortiSandbox PaaS builds (5.0.0–5.0.1, 4.4.0–4.4.7) and restrict/segment GUI access until upgraded. 🎯 Target: Global/Enterprises using FortiSandbox #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/fortisandbox-xss-vulnerability/

    Post summary

    Fortinet disclosed a high‑severity XSS flaw (CVE‑2025‑52436) that can lead to unauthenticated command execution in FortiSandbox; patches are released for affected builds and GUI access is restricted until upgrades.

    0000032
    191 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-52436 - High An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 t... https://www.thehackerwire.com/vulnerability/CVE-2025-52436/ https://t.co/eUFDqhaY73

    Post summary

    The tweet announces a high‑severity XSS vulnerability (CVE‑2025‑52436) in Fortinet FortiSandbox, detailing affected versions and CWE, but provides no PoC, exploit code, or patch information.

    0000062
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortisandbox---

Explore more