Fortinet released multiple security advisories covering FortiSandbox, FortiOS, FortiProxy, FortiPAM, and FortiAuthenticator, with the most serious issue tracked as CVE-2026-59835. The high-severity FortiSandbox flaw, rated CVSS 7.7 and classified as CWE-668, allows unauthenticated attackers to access the VNC server of malware-analysis virtual machines over the network, potentially exposing analysis sessions and interfering with sandbox operations. Fortinet said affected FortiSandbox versions are 5.0.0 through 5.0.2 and 4.4.3 through 4.4.8, while 5.2 and FortiSandbox PaaS are not affected; no in-the-wild exploitation has been reported.
The broader advisory set also addressed additional weaknesses including CVE-2026-59839, which could allow an authenticated CLI user to delete files from the root filesystem, along with lower-severity CRLF injection, path traversal, reflected XSS, buffer over-read, stack-based buffer overflow, and a FortiAuthenticator GUI out-of-bounds read affecting versions 6.6.0 through 6.6.2 and 6.5.0 through 6.5.7. Canada’s Cyber Centre echoed the vendor notice and urged administrators to review the advisories and apply updates, particularly because several affected Fortinet products are commonly deployed in enterprise and internet-facing security environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On July 14, 2026, the Canadian Centre for Cyber Security published advisory AV26-695 highlighting Fortinet advisories for FortiAuthenticator and FortiSandbox vulnerabilities. The notice identified affected version ranges and urged administrators to review Fortinet's advisories and apply the necessary updates.
On July 14, 2026, Fortinet disclosed seven security advisories affecting FortiOS, FortiProxy, FortiPAM, and FortiSandbox. The disclosures included several lower- and medium-severity issues as well as the more serious FortiSandbox unauthenticated VNC exposure and a FortiPAM flaw that could let an authenticated CLI user delete root filesystem files.
On July 14, 2026, Fortinet published advisory FG-IR-26-145 for CVE-2026-59835, a high-severity FortiSandbox flaw that exposes the VNC server of malware-scanning virtual machines to unauthenticated network attackers. Fortinet said affected versions include 5.0.0 through 5.0.2 and 4.4.3 through 4.4.8, credited INPS for reporting the issue, and reported no known in-the-wild exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcethecybersecguru.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcefortiguard.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.