Fortinet Patches 7 Security Flaws Affecting FortiOS, FortiProxy, FortiPAM, FortiSASE, and FortiSandbox
ID: 9605f9fd-6985-56b8-9e9f-01b0876863ed
STIX ID: report--9605f9fd-6985-56b8-9e9f-01b0876863ed
Feed Name: GBHackers
Fortinet published security advisories addressing seven vulnerabilities across FortiOS, FortiProxy, FortiPAM, FortiSASE, and FortiSandbox — the most critical is CVE-2026-59835 (high) which can expose VNC access on all interfaces in FortiSandbox, potentially allowing unauthenticated remote access; other flaws include authenticated path traversal (file deletion), buffer overread/overflow, reflected XSS in SSL‑VPN, and HTTP header injection. Administrators are urged to identify affected appliances, apply vendor-recommended fixes, restrict administrative/SSL‑VPN/GUI/VNC access to trusted networks, and review logs for suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
