started · updated
Critical flaws hit FortiSandbox, Microsoft Edge, Windows and Splunk
Fortinet disclosed a critical OS command‑injection vulnerability (CVE‑2026‑25089) in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS. The unauthenticated flaw can be triggered via crafted HTTP requests, receives a CVSS 9.8 rating and affects versions 4.2, 4.4‑4.8, 5.0‑5.5. Fortinet advises upgrading to FortiSandbox 5.0.6 or later.
Microsoft’s Edge 149 update removes the Drop file‑sharing feature, promotes the Copilot UI, and simultaneously patches 28 Chromium‑engine bugs, including five critical use‑after‑free flaws. The update arrives amid a broader June Patch‑Day that also addresses numerous enterprise‑focused security issues.
Splunk Enterprise issued CVE‑2026‑20253, a CVSS 9.8 flaw in the on‑premise PostgreSQL side‑car service that allows unauthenticated file creation and code execution. After a proof‑of‑concept exploit appeared on 12 June, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) placed the vulnerability in its active‑exploitation catalog and gave federal agencies a deadline to patch by the following Sunday.
Microsoft’s June 9 2026 Windows update (KB5094126/KB5095051) fixed a record‑high 208 security flaws, 38 of them critical, including CVE‑2026‑4341 in the CLFS driver and CVE‑2026‑4209 in Secure Boot. The same update introduced a UI bug in the Recycle Bin confirmation dialog, showing cryptic internal filenames, and caused ancillary issues such as BitLocker lockouts on some enterprise laptops.