CVE-2026-59835: A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-59835
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-598350.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-59835 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0245 [1.00] [M/H] Vulnerability fixed in Fortinet FortiSandboxncsc-nl
- high[NEW] [high] Fortinet FortiSandbox: Vulnerability allows bypassing security measurescert-bund
- unknownMultiple vulnerabilities in Fortinet products (July 15, 2026)cert-fr-avis
- unknownUnauthenticated VNC access exposed on all interfacesfortinet
Recent advisories for A exposure of
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-18059: The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to…nvd · 2026-08-01
- mediumCVE-2026-2916: The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure …nvd · 2026-08-01
- mediumCVE-2026-56569: HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public e…nvd · 2026-07-31
- lowCVE-2026-56568: HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messag…nvd · 2026-07-31
- mediumCVE-2026-56567: HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the…nvd · 2026-07-31
- highGHSA-4vmm-5qvc-w5p7: Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposureghsa · 2026-07-29
More from NVD Recent CVEs
- unknownCVE-2026-55735: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticat…2026-08-01
- unknownCVE-2026-55734: Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guar…2026-08-01
- unknownCVE-2026-55733: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- unknownCVE-2026-54894: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01