NCSC-2026-0245 [1.00] [M/H] Vulnerability fixed in Fortinet FortiSandbox
Fortinet has fixed a vulnerability in FortiSandbox. The vulnerability concerns an Exposure of Resource to Wrong Sphere (CWE-668) in the VNC server component used within the scanning virtual machines of FortiSandbox. Unauthenticated attackers can send network requests to gain access to the VNC server of these virtual machines. This may allow unauthorized viewing of sensitive scan activities. The vulnerability affects multiple versions of FortiSandbox, namely versions 5.0.0 to 5.0.2 and 4.4.3 to 4.4.8.
CSIRTS triage
- What
- An unauthenticated attacker can access the VNC server of FortiSandbox virtual machines, leading to unauthorized viewing of sensitive activities.
- Who is affected
- Deployments of FortiSandbox versions 5.0.0 to 5.0.2 and 4.4.3 to 4.4.8 are affected.
- Urgency
- Remediation is urgent due to the potential for unauthorized access to sensitive information.
- Action
- Update FortiSandbox to the latest version to address this vulnerability.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiSandbox
Get an email when a new FortiSandbox advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0245
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-598350.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-59835 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Fortinet FortiSandbox: Vulnerability allows bypassing security measurescert-bund
- unknownMultiple vulnerabilities in Fortinet products (July 15, 2026)cert-fr-avis
- highCVE-2026-59835: A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.…nvd
- unknownUnauthenticated VNC access exposed on all interfacesfortinet
Recent advisories for Fortinet FortiSandbox
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalexploitedCVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerabilitycisa-kev · 2026-07-16
- criticalexploitedCVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerabilitycisa-kev · 2026-07-16
- high[NEW] [high] Fortinet FortiSandbox: Vulnerability allows bypassing security measurescert-bund · 2026-07-15
- highCVE-2026-59835: A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.…nvd · 2026-07-14
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30