CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0245 [1.00] [M/H] Vulnerability fixed in Fortinet FortiSandbox

unknownCVE-2026-59835
Fortinet has fixed a vulnerability in FortiSandbox. The vulnerability concerns an Exposure of Resource to Wrong Sphere (CWE-668) in the VNC server component used within the scanning virtual machines of FortiSandbox. Unauthenticated attackers can send network requests to gain access to the VNC server of these virtual machines. This may allow unauthorized viewing of sensitive scan activities. The vulnerability affects multiple versions of FortiSandbox, namely versions 5.0.0 to 5.0.2 and 4.4.3 to 4.4.8.

CSIRTS triage

vendor: Fortinetproduct: FortiSandboxInformation disclosureaffected: 5.0.0 to 5.0.2, 4.4.3 to 4.4.8
What
An unauthenticated attacker can access the VNC server of FortiSandbox virtual machines, leading to unauthorized viewing of sensitive activities.
Who is affected
Deployments of FortiSandbox versions 5.0.0 to 5.0.2 and 4.4.3 to 4.4.8 are affected.
Urgency
Remediation is urgent due to the potential for unauthorized access to sensitive information.
Action
Update FortiSandbox to the latest version to address this vulnerability.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch FortiSandbox

Get an email when a new FortiSandbox advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-17
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0245

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-59835coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Fortinet FortiSandbox

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories