
Do you use Fortinet devices? Several security vulnerabilities have been patched in FortiOS, FortiProxy, FortiPAM, and FortiSandbox!
On July 14, 2026, Fortinet released official security advisories regarding seven new security vulnerabilities identified in its core security products — FortiOS, FortiProxy, FortiPAM, and FortiSandbox.
The discovered vulnerabilities include Path Traversal, Buffer Overflow, Cross-Site Scripting (XSS), CRLF Injection, as well as unauthenticated access to the VNC service. Although none of them have been rated as “Critical,” some affect security devices widely deployed in corporate networks, which is why experts strongly recommend applying updates as soon as possible.
Which products are affected?
The vulnerabilities have been identified in the following Fortinet products and versions:
- FortiOS 7.0–8.0;
- FortiProxy 7.2–7.6;
- FortiPAM 1.4–1.9;
- FortiSandbox 4.4–5.2.
These products perform critical functions such as protecting corporate networks, controlling internet traffic, managing privileged accounts, and analyzing suspicious files in an isolated environment. Therefore, any vulnerability in them can have a negative impact on overall network security.
Identified vulnerabilities
The vulnerabilities announced by Fortinet include:
- CVE-2025-43892 — Buffer Over-read vulnerability triggered through an authenticated user;
- CVE-2025-62675 — CRLF Injection (HTTP Response Splitting) on the Web Filter warning page;
- CVE-2025-62826 — CRLF Injection on the Captive Portal authentication page;
- CVE-2026-59839 — Path Traversal vulnerability via the CLI;
- CVE-2026-23573 — Reflected Cross-Site Scripting (XSS) on the SSL-VPN portal;
- CVE-2026-59837 — Stack-based Buffer Overflow during log report generation;
- CVE-2026-59835 — Unauthenticated VNC service exposed on all network interfaces on FortiSandbox devices.
Which vulnerabilities are the most dangerous?
According to experts, two cases among the announced vulnerabilities require particular attention.
CVE-2026-59835 — Unauthenticated VNC in FortiSandbox
This vulnerability is related to the Virtual Network Computing (VNC) service on FortiSandbox devices being accessible without authentication on all network interfaces.
If this service is exposed to the external network, an attacker could connect to the sandbox device’s console without any authentication.
FortiSandbox is typically used for malware analysis and executing suspicious files in a safe environment. Compromising such a system could threaten not only the sandbox itself but the entire security infrastructure.
CVE-2026-59839 — Path Traversal
This vulnerability allows an authenticated user with limited privileges to access restricted system directories via the CLI.
As a result, an attacker could:
- delete critical system files;
- disrupt device operation;
- cause a denial of service (DoS).
SSL-VPN and Captive Portal users are also at risk
The identified CVE-2026-23573 exists on the SSL-VPN portal and is a Reflected XSS vulnerability.
No authentication is required to exploit this flaw. An attacker could send a specially crafted link to a user, and if the user clicks on it, malicious JavaScript code would execute in their browser.
Such attacks can be used for:
- stealing session data;
- redirecting users to fraudulent pages;
- conducting phishing attacks;
- hijacking administrator sessions.
Additionally, CRLF Injection vulnerabilities on Web Filter and Captive Portal pages allow manipulation of HTTP responses. Although they are rated as low severity, when combined with other attack methods, they can significantly increase the overall risk.
What is the risk for enterprises?
Fortinet products provide network security for millions of organizations worldwide. Firewalls, SSL-VPN, and web proxies operate directly with the internet, making them a constant focus of cybercriminals.
In recent years, there have been numerous real-world cyberattacks exploiting vulnerabilities in Fortinet devices. Therefore, security advisories published by the company are often analyzed by attackers shortly after release, followed by exploitation attempts.
Unpatched devices may face the following risks:
- bypass of network security policies;
- theft of administrator sessions;
- execution of malicious code;
- exposure of confidential data;
- service disruptions;
- unauthorized access to the corporate network.
Protection recommendations
Fortinet and information security experts recommend that organizations take the following measures:
- Immediately install all announced security updates for FortiOS, FortiProxy, FortiPAM, and FortiSandbox.
- Prioritize updating SSL-VPN and Captive Portal services exposed to the internet.
- Restrict CLI management capabilities to trusted administrators only.
- Verify whether the VNC service on FortiSandbox devices is exposed to the external network and disable it if not required.
- Implement multi-factor authentication (MFA) for administrator accounts.
- Regularly analyze system logs and monitor for unusual activity.
- Continuously monitor new recommendations and additional security updates published by Fortinet PSIRT.
Conclusion
Although none of the seven vulnerabilities patched by Fortinet are classified as critical, some of them affect internet-facing security devices, posing a serious risk. In particular, the unauthenticated VNC in FortiSandbox, the Reflected XSS on SSL-VPN, and the CLI Path Traversal vulnerabilities, when combined with other attack techniques, could lead to the compromise of corporate infrastructure.
Therefore, all organizations using Fortinet products must apply security updates without delay, strictly control internet-exposed services, and maintain continuous network security monitoring. In cybersecurity practice, timely patching is often one of the most critical protective measures that can prevent a major cyber incident.



