Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3145 articles · 183089 vulns · 36/41 feeds (7d)
← Back to list
7.7
CVE-2026-59835
fortinet · fortisandbox

CVE-2026-59835: A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 th

Description

A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.

Affected Products

VendorProductVersions
fortinetfortisandbox5.0.0, 4.4.3, FortiSandbox 4.4.0 - 4.4.8, FortiSandbox 5.0.0 - 5.0.5, FortiAnalyzer Cloud 7.6.2 - 7.6.4, FortiManager Cloud 7.6.2 - 7.6.4, FortiDDoS-F 7.2.1 - 7.2.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
fortinetfortisandboxcert_advisory90%

References

  • https://fortiguard.fortinet.com/psirt/FG-IR-26-145

Related News (4 articles)

Tier B
BSI Advisories17d ago
[NEU] [hoch] Fortinet FortiSandbox: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
→ No new info (linked only)
Tier E
Reddit r/cybersecurity17d ago
FortiSandbox CVE-2026-59835 exposes sandbox VNC sessions without authentication
→ No new info (linked only)
Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits Fortinet (15 juillet 2026)
→ No new info (linked only)
Tier C
VulDB17d ago
CVE-2026-59835 | Fortinet FortiSandbox up to 4.4.8/5.0.2 VNC Server sandbox
→ No new info (linked only)
CVSS 3.17.7 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L/E:P/RL:O/RC:C
CISA KEV❌ No
Actively exploited❌ No
CWECWE-668, CWE-77, CWE-287, CWE-269, CWE-122, CWE-89
PublishedJul 14, 2026
Last enriched17d agov2
Tags
os command injectionauthentication bypassprivilege escalationheap-based buffer overflowsql injectionfortinetcritical vulnerability
Trending Score9
Source articles4
Independent4
Info Completeness9/14
Missing: epss, kev, exploit, patch, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-25089EXP
CVE-2026-25089: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
Trending: 83
MEDIUMCVE-2026-59837
CVE-2026-59837: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM
Trending: 7
MEDIUMCVE-2026-23573
CVE-2026-23573: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi
Trending: 6
MEDIUMCVE-2026-59839
CVE-2026-59839: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0
Trending: 6
HIGHCVE-2025-53379EXP
CVE-2025-53379: A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versio
Trending: 6

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: severity
Jul 14, 2026

Version History

v2
Last enriched 17d ago
v2Tier C17d ago

Updated severity from HIGH to MEDIUM and confirmed no exploit is available.

severity
via VulDB
v118d ago

Initial creation