logo

Critical Fortinet FortiSandbox Vulnerability Enables Code Execution Attacks

ID: 2d9d1b50-9eff-57af-bf05-84c2e3bf1654

STIX ID: report--2d9d1b50-9eff-57af-bf05-84c2e3bf1654

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Guru Baran

...
...

**Executive Summary:** Fortinet disclosed CVE-2026-26083, a critical (CVSS 9.1) missing-authorization flaw in the FortiSandbox web UI that allows unauthenticated remote attackers to execute arbitrary code or commands across on-premises, cloud, and PaaS deployments; numerous versions are affected and Fortinet recommends immediate patching or migration, while noting no observed in‑the‑wild exploitation to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.