FortiSandbox Web UI Command Injection Attempt (CVE-2026-25089)

Detects incoming HTTP requests to FortiSandbox administrative or management endpoints that contain suspicious shell metacharacters and command-injection patterns. These patterns are indicative of attempts to exploit CVE-2026-25089, an unauthenticated remote command injection vulnerability in the FortiSandbox Web UI.