ZeroHour
Product

FortiSandbox

5 mentions in 7 days · 5 in 30 days · 5 total · first seen · last

Timeline

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

Fortinet patched 10 vulnerabilities including two critical authentication flaws, CVE-2026-84390 (CVSS 9.6) and CVE-2026-84388 (CVSS 9.1), in FortiMonitorOnSight and the FortiPAM Chrome extension.

Fortinet's September patch release fixes CVE-2026-84390, a sensitive-information issue in the FortiMonitorOnSight web portal that lets unauthenticated attackers bypass authentication with forged or reused JWTs. CVE-2026-84388 is an improper authentication flaw in the Fortinet Privileged Access Agent Chrome extension that can allow attackers to proxy a user's browser traffic via a malicious website, requiring upgrades to both FortiPAM 1.9.1/1.8.4 and extension 8.0.1.123+. High-severity information disclosure in FortiSandbox (CVE-2026-26084) and man-in-the-middle risk in the FortiOS/FortiProxy Agentless ZTNA portal (CVE-2026-84393) were also fixed, alongside medium/low issues across FortiManager, FortiAnalyzer, FortiSOAR, FortiClient, FortiSIEM and others. Fortinet did not indicate any of the flaws are being exploited in the wild.

Fortinet security advisory (AV26-898)

Canadian Cyber Centre advisory AV26-898 flags Fortinet vulnerabilities across FortiOS, FortiProxy, FortiPAM, FortiSandbox and FortiMonitorOnSight, urging administrators to apply updates

The Canadian Centre for Cyber Security relayed Fortinet PSIRT advisories (AV26-898) listing vulnerabilities affecting FortiOS 7.6.1-7.6.6, FortiProxy 7.6.2-7.6.6, FortiPAM Chrome extensions 7.4/8.0, FortiSandbox 4.4 and 5.0, FortiSandbox Cloud and PaaS 5.0.4-5.0.5, and FortiMonitorOnSight 7.2. The bulletin does not detail individual CVEs or exploitation. Administrators and users are encouraged to review the linked Fortinet advisories and apply the necessary updates.

Fortinet FortiSandbox Vulnerability Allows Unauthenticated Attackers to Access Sensitive Information

Fortinet fixed CVE-2026-26084, an unauthenticated access-control flaw in FortiSandbox GUI rated 8.9 CVSS, with no known exploitation yet.

Fortinet disclosed CVE-2026-26084 (advisory FG-IR-26-166), a CWE-284 improper access control flaw in the GUI of FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS, rated 8.9 CVSS v3.1. An unauthenticated remote attacker can send specially crafted HTTP requests to control NAT rules and expose sensitive information. Affected versions include FortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5 (plus Cloud/PaaS 5.0.4-5.0.5), fixed in 4.4.9 and 5.0.6. Fortinet researcher Adham El Karn found the flaw internally and the September 8 advisory reports no known exploitation.

ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability

ZDI publishes ZDI-26-645 for CVE-2026-84387, an authenticated command injection RCE in Fortinet FortiSandbox via crontab backup, rated CVSS 7.2.

Zero Day Initiative published advisory ZDI-26-645 describing a command injection flaw in Fortinet FortiSandbox's write_remote_backup_to_crontab function. Remote authenticated attackers can execute arbitrary code through the cronValue parameter. ZDI rated the issue CVSS 7.2 and assigned CVE-2026-84387.

ZDI Published Advisoriesupdated · 6d agofirst · 6d agoAdvisory 2 sourcesCVE-2026-84387

FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests

Fortinet disclosed CVE-2026-26084 (CVSS 8.9), an unauthenticated information-disclosure flaw in the FortiSandbox web UI, urging upgrades.

Fortinet patched CVE-2026-26084, a CWE-284 improper access control flaw in the shared web UI of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that lets unauthenticated attackers read sensitive data via crafted HTTP requests. Affected releases include FortiSandbox 5.0.0-5.0.5 and 4.4.0-4.4.8, Cloud 5.0.4-5.0.5, and PaaS 5.0.4-5.0.5; fixes arrive in 5.0.6+ and 4.4.9+, while FortiSandbox 5.2 and Cloud 4.4 are unaffected. The issue was found internally by Fortinet's Product Security team, and the company reports no evidence of exploitation in the wild. Disclosure carries only confidentiality impact, but exposed sandbox configurations and logs could aid follow-on attacks.

Cyber Security Newsupdated · 6d agofirst · 6d agoVulnerability 2 sourcesCVE-2026-26084

Related CVEs

  • Improper Access Control in Fortinet FortiSandbox Exposes Sensitive Data
    CVE-2026-26084 is an improper access control flaw (CWE-284) in the web interface of Fortinet's FortiSandbox threat-analysis product line, affecting on-premises 4.4.x and 5.0.x releases as well as the FortiSandbox Cloud and PaaS offerings. An unauthenticated attacker can trigger it remotely by sending crafted HTTP requests to the affected FortiSandbox web service, bypassing access controls without needing credentials or user interaction. A successful attacker gains access to sensitive information handled by the appliance; Fortinet's critical 9.9 CVSS score also reflects a scope change with a high availability-impact component, so defenders should treat the practical impact as potentially broader than simple information disclosure. Any organization running affected versions of FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS is in scope, though the product's enterprise appliance/cloud deployment model means the affected population is far smaller than endpoint or firewall software. There is no evidence of exploitation so far: the flaw is not in CISA KEV, has no known public proof-of-concept, and EPSS assigns roughly a 0.2% probability of exploitation within 30 days.
    · Fortinet FortiSandbox 5.0.0 through 5.0.5 · Fortinet FortiSandbox 4.4.0 through 4.4.8moderate
  • Sensitive Information in Source Code in Fortinet FortiMonitorOnSight (CVSS 9.8)
    CVE-2026-84390 is a critical (CVSS 3.1: 9.8) information-disclosure flaw in Fortinet FortiMonitorOnSight in which sensitive information is included in the product's source code (CWE-540). An unauthenticated, network-located attacker who obtains that embedded material (e.g., secrets or credentials shipped with the code) can use it to gain improper access by subverting access controls; the CVSS vector requires no privileges or user interaction and rates the impact high on confidentiality, integrity, and availability. All FortiMonitorOnSight deployments running the affected 7.2.x releases listed by Fortinet (7.2.0 through 7.2.2 and 7.2.4 through 7.2.7) are affected. Fortinet has shipped fixes for this flaw, but there is no public proof-of-concept, the vulnerability is not in CISA KEV, and no exploitation in the wild is currently known.
    · Fortinet FortiMonitorOnSight 7.2.0 through 7.2.2 · Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7niche
  • Certificate Host-Mismatch Validation Flaw in FortiOS and FortiProxy ZTNA
    CVE-2026-84393 is an improper certificate validation flaw (CWE-297, host mismatch) in the ZTNA (Zero Trust Network Access) functionality of Fortinet FortiOS and FortiProxy, in which certificates are not correctly verified against the intended host. Per the related advisory headline, a network-adjacent or on-path attacker can exploit it to perform a man-in-the-middle attack against ZTNA connections, and the vendor describes the impact as information disclosure; the CVSS vector additionally rates confidentiality, integrity, and availability impact as high. Organizations running affected FortiOS 7.6.1 through 7.6.6 or FortiProxy 7.6.2 through 7.6.6 with ZTNA enabled are exposed. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.2% (5th percentile), so risk is currently low but patching is still warranted given the high CVSS score.
    · Fortinet FortiOS 7.6.1 through 7.6.6 · Fortinet FortiProxy 7.6.2 through 7.6.6large
  • High-Privilege Command Injection in Fortinet FortiSandbox
    CVE-2026-84387 is a command injection flaw (CWE-77) in Fortinet FortiSandbox in which special elements used in a command are not properly neutralized, allowing an attacker to inject and execute unauthorized commands or code on the appliance. The CVSS vector indicates the flaw is reachable over the network (AV:N) but requires the attacker to already hold high-privilege credentials (PR:H), such as an administrative account, with no user interaction required; the exact entry point in the product interface is not detailed in the available data. Successful exploitation carries high impact across confidentiality, integrity, and availability, effectively giving the attacker arbitrary command execution on a security appliance that handles untrusted analyzed files. All FortiSandbox deployments running versions 4.4.0 through 4.4.9, 5.0.0 through 5.0.6, or 5.2.0 are affected. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and EPSS estimates only about a 0.9% probability of exploitation in the next 30 days, so no active exploitation is currently known.
    · Fortinet FortiSandbox 5.2.0 · Fortinet FortiSandbox 5.0.0 through 5.0.6moderate

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.