logo

Critical Fortinet FortiSandbox Vulnerability Enables Code Execution Attacks

ID: a5c21cc7-c395-5278-87ea-fafa4fc41c47

STIX ID: report--a5c21cc7-c395-5278-87ea-fafa4fc41c47

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Abi naya

...
...

**FortiSandbox Authorization Vulnerability (CVE-2026-26083):** A critical missing-authorization flaw in Fortinet FortiSandbox (including Cloud and PaaS variants) allows unauthenticated remote attackers to send specially crafted HTTP requests and execute arbitrary commands; Fortinet published an advisory on May 12, 2026 with affected versions and required upgrades/migrations and provided patches and migration paths, and there are currently no reports of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.