# Fortinet patches critical FortiSandbox flaw

Published: 2026-09-09 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/e343799d-3a2b-5a7e-bf85-3c317b46d251/fortinet-patches-critical-fortisandbox-flaw

> Fortinet fixed multiple vulnerabilities across its Forti-product line, including a critical unauthenticated FortiSandbox flaw that exposes sensitive data over the network.

NCSC-NL published an advisory summarizing a batch of Fortinet security fixes spanning FortiAnalyzer, FortiOS, FortiPAM, FortiProxy, FortiSandbox, FortiManager, FortiManager Cloud, FortiMonitor, FortiClient Windows, FortiSIEM and FortiSOAR. The issues cover a range of weakness classes including command injection, improper certificate validation with host mismatch, use of uninitialized variables, NULL pointer dereference, sensitive information exposure in source code, and open redirect.

The most significant issue, CVE-2026-26084, is an authorization vulnerability in FortiSandbox that allows an unauthenticated attacker to access sensitive information via specially crafted HTTP requests. It requires no user interaction and is exploitable remotely over the network, with a CVSS score listed as 9.9 in Fortinet's per-CVE data (the advisory text cites 8.9). No in-the-wild exploitation is reported at this time; this is a coordinated vendor patch release.

Fortinet has released updates for the affected products (FortiOS, FortiPAM, FortiProxy, FortiAnalyzer, FortiSandbox, FortiMonitor and FortiManager). Defenders running any of the listed Fortinet products should prioritize patching FortiSandbox instances given the unauthenticated, network-exploitable nature of CVE-2026-26084, and review the referenced FortiGuard PSIRT advisories (FG-IR-26-164 through FG-IR-26-174) for version-specific fix details across the remaining CVEs.

## Mentioned in this report

- Vulnerabilities: CVE-2026-22575, CVE-2026-26084, CVE-2026-84385, CVE-2026-84386, CVE-2026-84387, CVE-2026-84389, CVE-2026-84390, CVE-2026-84391, CVE-2026-84392, CVE-2026-84393

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0355.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e343799d-3a2b-5a7e-bf85-3c317b46d251/fortinet-patches-critical-fortisandbox-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
