Global software providers Fortinet, Ivanti, and SAP have released emergency patches to address a series of critical vulnerabilities across their product suites. These updates are intended to mitigate security flaws that could facilitate arbitrary code execution and the disclosure of sensitive information if left unaddressed. The releases follow the discovery of various bugs that pose significant risks to enterprise perimeter security and internal application management.
Among the most severe issues is a command injection vulnerability identified in Fortinet's FortiSandbox ecosystem. Specifically affecting the Web UI of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS, the flaw is tracked as CVE-2026-25089. It has been assigned a CVSS score of 9.1, indicating a critical level of severity. This vulnerability could allow an attacker to execute commands via the web interface, potentially compromising the sandboxing environment used to analyze suspicious files.
Ivanti and SAP have likewise targeted multiple high-priority vulnerabilities within their own software portfolios. These patches are designed to close gaps that could lead to unauthorized system access or data leaks. The coordinated release emphasizes the ongoing necessity for maintaining the most recent software versions across infrastructure components to prevent the exploitation of known weaknesses in enterprise software.
For CIOs and IT directors, these updates represent a critical maintenance requirement to preserve the integrity of the corporate network. Operations leaders and MSPs should review the specific impacted versions of FortiSandbox and other affected software to prioritize patching schedules. Ensuring these security updates are applied is essential for mitigating the risk of code execution attacks and protecting sensitive enterprise data from disclosure.
