Patch Tuesday-Adjacent: FortiSandbox, Ivanti, and SAP Ship Fixes for Critical Bugs
A 9.1-rated command injection in FortiSandbox headlines a busy week of vendor advisories. Most of these land squarely on platform teams.

Three more advisories hit the queue this week, and they're the kind that platform teams will be triaging while the security org writes the email about triaging them.
Fortinet shipped a fix for a command injection bug in the FortiSandbox web UI, covering the on-prem appliance, FortiSandbox Cloud, and the PaaS offering. It's CVE-2026-25089, CVSS 9.1. The failure mode here is the usual one: improper neutralization of special elements in a privileged interface, which lets an authenticated attacker execute arbitrary code or commands via crafted requests. If you're running FortiSandbox as your detonation tier — and a lot of shops do, because it sits behind the perimeter and gets implicitly trusted — that's a nasty pivot point.
Ivanti and SAP rounded out the batch with their own critical-rated fixes affecting arbitrary code execution and information disclosure paths. Specifics vary across the product lines, so check the vendor advisories against your actual deployed versions before someone in change management tells you the CMDB says you're not affected.
A few things worth saying out loud.
FortiSandbox is not an edge product in the way FortiGate is, but it is reachable from the management plane, and management planes are exactly where lateral movement playbooks live. In practice, most orgs have the sandbox UI exposed to an internal admin VLAN that half the SOC and half the network team can reach. That's the blast radius.
The PaaS variant is more interesting. Fortinet operates the control plane, but customers still own their tenant configuration and whatever integrations they've wired up. Expect the vendor advisory to say it's already mitigated on the hosted side. Expect your auditor to still ask for evidence.
For Ivanti, the pattern is by now familiar. Edge appliances, MDM, secure access — anything Ivanti ships has been a 2024 and 2025 story, and threat actors have shown they'll weaponize n-day Ivanti bugs inside of a week. Treat the patch window as a fire drill, not a maintenance window.
SAP advisories tend to get ignored by the security press because nobody wants to read about NetWeaver. The people who do read them are ransomware affiliates looking for unpatched ERP boxes with domain trust. Don't be the postmortem that says "SAP patches were on a quarterly cycle."
One thing the post-mortem will say, if you skip this round: the CVE was public, the CVSS was 9.1, and the patch was available.
Operational takeaway: pull your FortiSandbox, Ivanti, and SAP inventory today, map it to the advisories, and put a hard SLA on the criticals — not a ticket in the backlog.



