Fortinet released security updates for vulnerabilities affecting FortiOS, FortiProxy, FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. Italy's national CSIRT reported that the set includes one critical and one high-severity issue that could expose sensitive information; affected FortiOS and FortiProxy versions include 7.6.x before 7.6.7, while affected FortiSandbox releases include 5.0.x before 5.0.6 and 4.4.x before 4.4.9.
One disclosed issue, CVE-2026-26084, is a high-severity improper-access-control flaw in the FortiSandbox web interface, rated CVSS 8.9. Unauthenticated remote attackers could use crafted HTTP requests to reach internal API endpoints and retrieve sensitive information without credentials or user interaction. Fortinet reported no evidence of active exploitation and credited internal researcher Adham El Karn; the Canadian Centre for Cyber Security also urged administrators to review Fortinet PSIRT advisories and promptly apply relevant updates across affected Fortinet products.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-898 covering vulnerabilities in multiple Fortinet products and directed administrators to review Fortinet PSIRT advisories and apply required security updates.
Multiple Fortinet products were identified as affected by vulnerabilities, including FortiOS and FortiProxy 7.6.1–7.6.6, FortiPAM Chrome Extension 7.4 and 8.0, FortiSandbox product releases, and FortiMonitorOnSight 7.2 releases.
Fortinet released security updates for vulnerabilities, including one critical and one high-severity issue, affecting FortiOS, FortiProxy, FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. The updates address flaws that could allow access to sensitive information, with FortiOS and FortiProxy fixed in 7.6.7 and affected FortiSandbox 5.0 and 4.4 releases fixed in 5.0.6 and 4.4.9, respectively.
Fortinet disclosed CVE-2026-26084, a CVSS 8.9 improper-access-control vulnerability in the FortiSandbox web interface that could let unauthenticated attackers use crafted HTTP requests to obtain sensitive information from internal API endpoints. Fortinet credited Product Security researcher Adham El Karn, said it had no evidence of exploitation in the wild, and provided fixed releases including FortiSandbox 5.0.6 and 4.4.9.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourceacn.gov.it
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcecirt.gy
Open sourcefortiguard.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.