Fortinet Patches Seven Vulnerabilities Across FortiOS, FortiProxy, FortiPAM, and FortiSandbox
Fortinet has released security updates for seven vulnerabilities affecting FortiOS, FortiProxy, FortiPAM, and FortiSandbox. The July 14, 2026, release includes one high-severity vulnerability, four medium-severity flaws, and two low-severity issues.
The most serious vulnerability exposes the VNC servers of virtual machines used by FortiSandbox to scan files. An unauthenticated attacker could reach those servers remotely on vulnerable systems.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
Fortinet has not reported active exploitation of the seven vulnerabilities. However, administrators should review the company’s July 2026 PSIRT advisories and install the recommended upgrades, particularly on systems accessible from untrusted networks.
Seven Fortinet vulnerabilities disclosed
The vulnerabilities cover several attack paths, including exposed services, cross-site scripting, path traversal, memory disclosure, buffer overflow, and HTTP response splitting.
| CVE | Affected products | Vulnerability | CVSS | Severity |
|---|---|---|---|---|
| CVE-2025-43892 | FortiOS | Buffer over-read in authd and wad | 4.1 | Medium |
| CVE-2025-62675 | FortiOS, FortiProxy | HTTP response splitting in the Web Filter warning page | 3.4 | Low |
| CVE-2025-62826 | FortiOS, FortiProxy | HTTP response splitting in the captive portal form | 3.1 | Low |
| CVE-2026-59839 | FortiOS, FortiProxy, FortiPAM | Path traversal through a CLI command | 5.5 | Medium |
| CVE-2026-23573 | FortiOS, FortiProxy, FortiPAM | Reflected cross-site scripting | 6.1 | Medium |
| CVE-2026-59837 | FortiOS, FortiProxy, FortiPAM | Stack buffer overflow in log reports | 5.9 | Medium |
| CVE-2026-59835 | FortiSandbox | Unauthenticated access to VNC servers | 8.6 | High |
FortiSandbox VNC exposure carries the highest risk
CVE-2026-59835 affects FortiSandbox 5.0.0 through 5.0.2 and versions 4.4.3 through 4.4.8. The flaw exposes the VNC servers of virtual machines that FortiSandbox uses during file scanning.
According to the FortiSandbox VNC advisory, a remote attacker does not need credentials or user interaction to reach the exposed service. Successful exploitation could compromise the confidentiality of data inside a scanning virtual machine and may also affect its integrity or availability.
The vulnerability received a CVSS 3.1 score of 8.6. Organizations should upgrade FortiSandbox 5.0 installations to version 5.0.3 or later and FortiSandbox 4.4 installations to version 4.4.9 or later.
Cross-site scripting requires user interaction
CVE-2026-23573 is a reflected cross-site scripting vulnerability affecting FortiOS, FortiProxy, and FortiPAM. An attacker could prepare a malicious request that runs code in a victim’s browser after the victim interacts with it.
The vulnerability has a network-based attack vector and does not require prior privileges, but successful exploitation requires user action. Fortinet’s cross-site scripting advisory assigns it a CVSS score of 6.1.
Affected releases include FortiOS 7.2, 7.4, and versions 7.6.0 through 7.6.6. Some older FortiProxy and FortiPAM branches also contain the flaw. Administrators should consult Fortinet’s upgrade table because the corrected version differs by product branch.
Path traversal needs physical access and elevated privileges
CVE-2026-59839 is a path traversal vulnerability in a CLI command used by FortiOS, FortiProxy, and FortiPAM. It could allow an attacker to delete files outside the command’s intended directory.
Fortinet’s path traversal advisory gives the flaw a CVSS score of 5.5. Its attack requirements limit the immediate risk: the attacker needs physical access and a highly privileged account.
Deleting sensitive files could still disrupt the appliance or damage its configuration. Organizations should tightly restrict console access, review privileged administrator accounts, and install the relevant update.
Buffer overflow could allow code execution
CVE-2026-59837 is a stack-based buffer overflow in the log report feature. It affects older releases of FortiOS, FortiProxy, and FortiPAM.
A privileged authenticated attacker could send crafted HTTP requests and potentially execute unauthorized code or commands. However, exploitation also requires the attacker to overcome protections such as address space layout randomization and stack protection, according to the Fortinet log report advisory.
The vulnerability carries a CVSS score of 5.9. Despite the added exploitation requirements, successful code execution on a security appliance could give an attacker broad control over the affected device.
Two flaws allow HTTP response splitting
CVE-2025-62675 and CVE-2025-62826 involve improper handling of carriage return and line feed characters in HTTP headers. Attackers could use these flaws to inject arbitrary headers into responses generated by FortiOS or FortiProxy.
For CVE-2025-62675, the attacker must possess a valid web filter override token and convince a user to open a crafted link. The Web Filter warning page advisory rates the vulnerability as low severity with a CVSS score of 3.4.
CVE-2025-62826 affects captive portal authentication. Exploitation requires an attacker who can intercept and modify a user’s authentication request, which considerably limits practical attacks. Fortinet assigned it a CVSS score of 3.1.
Buffer over-read could expose device memory
CVE-2025-43892 affects the authd and wad daemons in FortiOS. An authenticated remote attacker could submit a specially crafted request and cause part of the appliance’s memory to appear in a redirect response.
Exposed memory may contain information that helps an attacker plan another attack. Fortinet rates the vulnerability as medium severity with a CVSS score of 4.1.
The flaw affects FortiOS 7.2, versions 7.4.0 through 7.4.8, and versions 7.6.0 through 7.6.2. Administrators should upgrade to a corrected release in the same supported branch.
What Fortinet administrators should do
Organizations should inventory all FortiOS, FortiProxy, FortiPAM, and FortiSandbox appliances before applying the updates. Administrators can then compare each installed release against the affected-version tables in Fortinet’s PSIRT catalog.
Security teams should prioritize the following actions:
- Upgrade vulnerable FortiSandbox systems immediately, starting with appliances reachable from untrusted networks.
- Block unnecessary access to VNC and management services at network boundaries.
- Limit CLI, console, and administrative access to trusted personnel and management networks.
- Review logs for unexpected VNC connections, crafted web requests, file deletion, and unusual administrator activity.
- Replace unsupported product branches that no longer receive security fixes.
Administrators should not rely only on a vulnerability’s severity label. Access requirements reduce the likelihood of some attacks, but compromised administrator credentials or weak network controls could still make the medium-severity flaws valuable to an attacker.
FAQ
The vulnerabilities affect selected versions of FortiOS, FortiProxy, FortiPAM, and FortiSandbox. The affected releases differ for each CVE, so administrators should compare their installed versions with Fortinet’s advisory tables.
CVE-2026-59835 carries the highest severity rating. It could allow an unauthenticated remote attacker to access VNC servers used by vulnerable FortiSandbox scanning virtual machines.
Fortinet had not reported known exploitation when it published the advisories. Organizations should still patch promptly because public vulnerability details can help attackers develop exploits.
CVE-2026-59835 affects FortiSandbox versions 5.0.0 through 5.0.2 and versions 4.4.3 through 4.4.8. Fortinet recommends upgrading to version 5.0.3, version 4.4.9, or a later supported release.
Organizations should patch the FortiSandbox VNC exposure first, followed by internet-facing and management-accessible systems. They should also restrict administrative access and monitor appliances for unusual connections or configuration changes.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages