CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-59838

mediumCVSS 5.9covered by 4 sourcesfirst seen 2026-07-14
CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted requests. Revised on 2026-07-14 00:00:00

CSIRTS triage

What
A privileged administrator may execute unauthorized commands via crafted requests.
Who is affected
Privileged administrators using FortiSIEM.
Urgency
Remediation is important due to the potential for unauthorized command execution.
Action
Update FortiSIEM to the latest version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-59838

Get an email if CVE-2026-59838 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (4)

External references

NVD record for CVE-2026-59838

CVE.org record

Embed the live status

CVE-2026-59838 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-59838 status](https://www.csirts.com/badge/CVE-2026-59838)](https://www.csirts.com/cve/CVE-2026-59838)