# Critical Zero-Auth RCE Flaws in Fortinet and Ivanti Demand Immediate Patching


## The Threat


Fortinet and Ivanti have released emergency patches for multiple critical vulnerabilities, including two remote code execution flaws that require zero authentication and can be exploited over the network. The most severe is a command injection bug in Ivanti Sentry with a perfect CVSS 10.0 score—the highest possible rating—that allows unauthenticated attackers to execute arbitrary commands with root privileges on vulnerable appliances.


These vulnerabilities target enterprise security and management products that sit at the perimeter of networks, making them particularly attractive targets. Fortinet's FortiSandbox, a malware analysis and sandboxing platform trusted by thousands of organizations, suffers from CVE-2026-25089, a critical OS command injection flaw accessible to remote attackers without credentials. Simultaneously, Ivanti's Sentry—a remote access and multi-factor authentication appliance—is affected by two critical flaws: one allowing unauthenticated command injection (CVE-2026-10520) and another enabling remote attackers to create administrative accounts without any authentication (CVE-2026-10523).


The timing and severity of these disclosures underscore a growing trend in 2026: enterprise appliances—the devices organizations deploy specifically to improve security—are becoming high-value attack targets. Both vendors emphasize no evidence of active exploitation exists, but the zero-authentication requirement means these flaws pose immediate risk the moment they become public knowledge. Organizations running these products should treat patching as an emergency priority.


## Severity and Impact


| Vulnerability | CVE | Product | CVSS Score | CVSS Vector | Attack Complexity | Authentication Required |

|---|---|---|---|---|---|---|

| OS Command Injection (FortiSandbox) | CVE-2026-25089 | FortiSandbox, Cloud, PaaS WEB UI | 9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | Low | None |

| OS Command Injection (Sentry) | CVE-2026-10520 | Ivanti Sentry | 10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | Low | None |

| Authentication Bypass (Sentry) | CVE-2026-10523 | Ivanti Sentry | 9.9 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | Low | None |

| Arbitrary Apache Directives (EPMM) | CVE-2026-6973 | Ivanti Endpoint Manager Mobile | 8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | Low | Yes |

| Command Execution via Script (FortiOS/FortiProxy) | Fortinet Medium Severity | FortiOS, FortiProxy | 6.5 | Medium vector | Low | Yes |

| Config Disclosure (FortiPortal API) | Fortinet Medium Severity | FortiPortal API | Medium | Medium vector | Low | Yes |

| Root Privilege Execution (EPMM) | CVE-2026-10727 | Ivanti Endpoint Manager Mobile | 8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | Low | Yes |


## Affected Products


Fortinet:

  • FortiSandbox versions prior to 5.0.6 or 4.4.9
  • FortiSandbox Cloud version prior to 5.0.6
  • FortiSandbox PaaS WEB UI version prior to 5.0.6
  • FortiOS (all versions with the medium-severity script execution flaw)
  • FortiProxy (all versions with the medium-severity script execution flaw)
  • FortiPortal API (all versions with the medium-severity configuration disclosure flaw)

  • Ivanti:

  • Sentry versions prior to 10.5.2, 10.6.2, or 10.7.1 (depending on branch)
  • Endpoint Manager Mobile (EPMM) versions prior to 12.9.0.1, 12.8.0.3, or 12.7.0.2

  • ## Mitigations


    Immediate actions (within 24 hours):

    1. Patch without delay. For Ivanti Sentry and Fortinet FortiSandbox, treat patches as emergency—these devices are directly exposed to the internet on most networks and require immediate updating.

    2. Verify you are running vulnerable versions. Check your appliance firmware version against the affected ranges listed above.

    3. If patching cannot occur immediately, implement strict network access controls. Restrict access to FortiSandbox and Sentry management interfaces to trusted administrative networks only.


    Secondary controls:

  • Monitor authentication logs for unexpected account creation (Ivanti Sentry CVE-2026-10523 exploit signature: new admin users created without administrative action).
  • Enable verbose command logging on affected appliances to detect command injection attempts.
  • Review firewall rules; these appliances should never be directly accessible from untrusted networks.
  • For Ivanti EPMM, ensure only trusted administrative credentials are active and validate no unauthorized Apache directives exist in configurations.

  • Long-term:

  • Subscribe to vendor security advisories and implement a structured patching schedule for edge devices (these are often neglected in update cycles).
  • Consider segmenting sandboxing and VPN appliances on isolated management networks with explicit jump-box access.

  • ## References


  • Fortinet Security Advisories: https://www.fortiguard.com/psirt
  • Ivanti Security Advisories: https://forums.ivanti.com/s/cgi-bin/WebObjects/CgiStart
  • NVD CVE-2026-25089: https://nvd.nist.gov/vuln/detail/CVE-2026-25089
  • NVD CVE-2026-10520: https://nvd.nist.gov/vuln/detail/CVE-2026-10520
  • NVD CVE-2026-10523: https://nvd.nist.gov/vuln/detail/CVE-2026-10523

  • ---


    ## HackWire Analysis


    What's striking about this advisory cycle is not just the severity—CVSS 10.0 is rare—but the pattern it represents. Both vulnerabilities target appliances sitting at the network perimeter, and both allow unauthenticated remote code execution. Ivanti Sentry's authentication bypass (CVE-2026-10523) is particularly concerning because it doesn't just give attackers command execution; it gives them persistent admin access. An attacker exploiting this flaw could create a privileged account and maintain presence indefinitely, bypassing the entire purpose of the VPN appliance.


    The FortiSandbox vulnerability is equally dangerous from a different angle. Malware sandboxes are supposed to be trusted infrastructure—security teams use them to detonate suspicious files safely. An OS command injection in the sandbox WEB UI means an attacker can potentially compromise the sandbox's analysis reports, poison threat intelligence data, or pivot from the sandbox into internal networks. In a ransomware or APT context, this is a critical supply-chain vulnerability: compromising the analysis tool compromises the organization's security visibility.


    For organizations, the lesson is blunt: appliances marketed as security tools—VPN gateways, sandboxes, firewalls—are now preferred targets because success grants immediate network access and often requires no authentication. Patch Tuesday patches on Patch Tuesday; this should be *Appliance Emergency*. If your organization is running Ivanti Sentry or Fortinet FortiSandbox, patching today is not optional—these are internet-facing, authentication-bypassed RCE flaws. If you cannot patch immediately, you need air-gapped or restricted-access configurations *now*, not tomorrow.


    The fact that neither vendor reports active exploitation is encouraging, but these disclosures are public. Nation-state threat actors and ransomware groups monitor vendor advisories closely. Organizations still running unpatched versions within 48 hours are high-priority targets.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)