Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3145 articles · 183089 vulns · 36/41 feeds (7d)
← Back to list
5.0
CVE-2026-59839PATCHED
Fortinet · FortiProxy

CVE-2026-59839: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0

Description

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Affected Products

VendorProductVersions
FortinetFortiProxy7.6.0, 7.4.0, 7.2.0, 7.0.0, 7.6.0, 7.4.0, 7.2.0, 7.0.0, 6.4.0, 1.8.0, 1.7.0, 1.6.0, 1.5.0, 1.4.0, 1.3.0, 1.2.0, 1.1.0, 1.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
fortinetfortiosmitre_affected90%
fortinetfortipammitre_affected90%
fortinetfortiproxycert_advisory90%

References

  • https://fortiguard.fortinet.com/psirt/FG-IR-26-151

Related News (4 articles)

Tier B
BSI Advisories17d ago
[NEU] [mittel] Fortinet FortiOS und FortiProxy: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits Fortinet (15 juillet 2026)
→ No new info (linked only)
Tier C
VulDB17d ago
CVE-2026-59839 | Fortinet FortiOS/FortiPAM/FortiProxy Pathname path traversal
→ No new info (linked only)
Tier A
Fortinet PSIRT18d ago
Path traversal in CLI command allows deletion of root file system
→ No new info (linked only)
CVSS 3.15.0 MEDIUM
VectorCVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H/E:P/RL:O/RC:C
CISA KEV❌ No
Actively exploited❌ No
Patch available
7.6.7
CWECWE-22
PublishedJul 14, 2026
Last enriched18d agov2
Trending Score6
Source articles4
Independent4
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-25089EXP
CVE-2026-25089: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
Trending: 83
HIGHCVE-2026-59835
CVE-2026-59835: A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 th
Trending: 9
MEDIUMCVE-2026-59837
CVE-2026-59837: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM
Trending: 7
MEDIUMCVE-2026-23573
CVE-2026-23573: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi
Trending: 6
HIGHCVE-2025-53379EXP
CVE-2025-53379: A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versio
Trending: 6

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: affectedVersions, patchAvailable
Jul 14, 2026
Patch Available
Jul 14, 2026

Version History

v2
Last enriched 18d ago
v2Tier A18d ago

Added affected version 8.0 and updated patch available to 7.6.7.

affectedVersionspatchAvailable
via Fortinet PSIRT
v118d ago

Initial creation