CVE-2026-59841
CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute arbitrary code via spoofing the supervisors hostname when the Windows device is configured with the 'Supers Override' feature. Revised on 2026-07-14 00:00:00
CSIRTS triage
- What
- An improper restriction vulnerability may allow an attacker to execute arbitrary code.
- Who is affected
- Users of FortiSIEM Windows Agent on the same local network.
- Urgency
- Remediation is necessary due to the potential for arbitrary code execution.
- Action
- Review and apply any available updates or mitigations.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-59841
Get an email if CVE-2026-59841 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
Advisory coverage (5)
- medium[NEW] [medium] Fortinet FortiSIEM: Multiple vulnerabilitiescert-bund · 2026-07-16
- unknownNCSC-2026-0240 [1.00] [M/H] Vulnerabilities fixed in multiple Fortinet productsncsc-nl · 2026-07-15
- unknownMultiple vulnerabilities in Fortinet products (July 15, 2026)cert-fr-avis · 2026-07-15
- highCVE-2026-59841: A improper restriction of communication channel to intended endpoints vulnerability in Fortine…nvd · 2026-07-14
- unknownSupers override fails to properly override supervisor addressfortinet · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-59841)