Fortinet patches critical FortiSandbox flaw
Fortinet fixed multiple vulnerabilities across its Forti-product line, including a critical unauthenticated FortiSandbox flaw that exposes sensitive data over the network.
NCSC-NL published an advisory summarizing a batch of Fortinet security fixes spanning FortiAnalyzer, FortiOS, FortiPAM, FortiProxy, FortiSandbox, FortiManager, FortiManager Cloud, FortiMonitor, FortiClient Windows, FortiSIEM and FortiSOAR. The issues cover a range of weakness classes including command injection, improper certificate validation with host mismatch, use of uninitialized variables, NULL pointer dereference, sensitive information exposure in source code, and open redirect.
The most significant issue, CVE-2026-26084, is an authorization vulnerability in FortiSandbox that allows an unauthenticated attacker to access sensitive information via specially crafted HTTP requests. It requires no user interaction and is exploitable remotely over the network, with a CVSS score listed as 9.9 in Fortinet's per-CVE data (the advisory text cites 8.9). No in-the-wild exploitation is reported at this time; this is a coordinated vendor patch release.
Fortinet has released updates for the affected products (FortiOS, FortiPAM, FortiProxy, FortiAnalyzer, FortiSandbox, FortiMonitor and FortiManager). Defenders running any of the listed Fortinet products should prioritize patching FortiSandbox instances given the unauthenticated, network-exploitable nature of CVE-2026-26084, and review the referenced FortiGuard PSIRT advisories (FG-IR-26-164 through FG-IR-26-174) for version-specific fix details across the remaining CVEs.
Mentioned in this report
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0355.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free