CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-59835

highCVSS 8.6covered by 5 sourcesfirst seen 2026-07-14
CVSSv3 Score: 7.7 An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSandbox may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests. Revised on 2026-07-14 00:00:00

CSIRTS triage

What
An unauthenticated attacker may access the VNC server of VMs performing scanning via network requests.
Who is affected
Deployments of FortiSandbox with VNC access enabled.
Urgency
Remediation is urgent due to the potential for unauthorized access.
Action
Restrict VNC access to authenticated users only.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-59835

Get an email if CVE-2026-59835 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (5)

External references

NVD record for CVE-2026-59835

CVE.org record

Embed the live status

CVE-2026-59835 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-59835 status](https://www.csirts.com/badge/CVE-2026-59835)](https://www.csirts.com/cve/CVE-2026-59835)