CVE-2025-46215: Fortinet FortiSandbox
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to evade the sandboxing scan via a crafted file.
Affected products
- Fortinet FortiSandbox: from 4.0.0, before 4.4.8 (fixed in 4.4.8); from 5.0.0, before 5.0.2 (fixed in 5.0.2)
Published 2025-11-18. Last modified 2026-06-17.