ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Fortinet FortiSandbox authenticated RCE CVE-2026-84387 (CVSS 7.2) detailed by ZDI as Canadian Cyber Centre urges broad Fortinet patching via AV26-898

mediumAdvisoryimportance 26CVE-2026-84387
What's new: First merged summary for this story. New on 2026-09-09: ZDI published technical advisory ZDI-26-645 for CVE-2026-84387, an authenticated command injection RCE (CVSS 7.2) in FortiSandbox's crontab backup function, and the Canadian Centre for Cyber Security issued AV26-898 urging review of Fortinet PSIRT advisories and patching across FortiOS, FortiProxy, FortiPAM, FortiSandbox and…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

ZDI published ZDI-26-645 for CVE-2026-84387, an authenticated command injection RCE rated CVSS 7.2 in Fortinet FortiSandbox's write_remote_backup_to_crontab function, while the Canadian Centre for Cyber Security's advisory AV26-898 urged updates across…

On 2026-09-09 (2026-09-09T05:00:00Z), Zero Day Initiative published advisory ZDI-26-645 describing a command injection vulnerability in Fortinet FortiSandbox's write_remote_backup_to_crontab function, tracked as CVE-2026-84387. Remote authenticated attackers can execute arbitrary code through the cronValue parameter, and ZDI rated the issue CVSS 7.2. Separately, later the same day (2026-09-09T13:48:46Z), the Canadian Centre for Cyber Security issued advisory AV26-898 relaying Fortinet PSIRT advisories covering FortiOS 7.6.1-7.6.6, FortiProxy 7.6.2-7.6.6, FortiPAM Chrome extensions 7.4/8.0, FortiSandbox 4.4 and 5.0, FortiSandbox Cloud and PaaS 5.0.4-5.0.5, and FortiMonitorOnSight 7.2, and encouraging administrators and users to review the linked Fortinet advisories and apply the necessary updates. The two reports do not contradict each other, but they differ in specificity: the Canadian bulletin does not detail individual CVEs or exploitation and does not state whether it covers CVE-2026-84387, while only the ZDI report provides CVE identifiers, severity scoring and technical detail. No exploitation details, affected-version detail for the ZDI CVE, or patch status were stated in either report.

  • ZDI advisory ZDI-26-645 (published 2026-09-09T05:00:00Z) describes a command injection RCE in Fortinet FortiSandbox's write_remote_backup_to_crontab function, exploitable by remote authenticated attackers via the cronValue parameter.
  • The ZDI-tracked vulnerability is CVE-2026-84387, rated CVSS 7.2.
  • Canadian Centre for Cyber Security advisory AV26-898 (published 2026-09-09T13:48:46Z) relays Fortinet PSIRT advisories and urges prompt patching.
  • AV26-898 lists affected products/versions: FortiOS 7.6.1-7.6.6, FortiProxy 7.6.2-7.6.6, FortiPAM Chrome extensions 7.4/8.0, FortiSandbox 4.4 and 5.0, FortiSandbox Cloud and PaaS 5.0.4-5.0.5, and FortiMonitorOnSight 7.2.
  • AV26-898 provides no specific CVE identifiers or exploitation details and directs users to the linked Fortinet advisories for update information.
  • The Canadian bulletin covers FortiSandbox but does not tie its listed versions to any specific CVE, so it is not stated whether AV26-898 includes CVE-2026-84387.
  • Both reports were published on 2026-09-09; neither states whether the vulnerabilities have been exploited in the wild.

Coverage timeline

  1. · 6d ago
    ZDI Published Advisories· 26
    ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability

    ZDI publishes ZDI-26-645 for CVE-2026-84387, an authenticated command injection RCE in Fortinet FortiSandbox via crontab backup, rated CVSS 7.2.

  2. · 6d ago
    Canadian Centre for Cyber Security· 26
    Fortinet security advisory (AV26-898)

    Canadian Cyber Centre advisory AV26-898 flags Fortinet vulnerabilities across FortiOS, FortiProxy, FortiPAM, FortiSandbox and FortiMonitorOnSight, urging administrators to apply updates

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-84387
High-Privilege Command Injection in Fortinet FortiSandbox

CVE-2026-84387 is a command injection flaw (CWE-77) in Fortinet FortiSandbox in which special elements used in a command are not properly neutralized, allowing an attacker to inject and execute unauthorized commands or code on the appliance. The CVSS vector indicates the flaw is reachable over the network (AV:N) but requires the attacker to already hold high-privilege credentials (PR:H), such as an administrative account, with no user interaction required; the exact entry point in the product interface is not detailed in the available data. Successful exploitation carries high impact across confidentiality, integrity, and availability, effectively giving the attacker arbitrary command execution on a security appliance that handles untrusted analyzed files. All FortiSandbox deployments running versions 4.4.0 through 4.4.9, 5.0.0 through 5.0.6, or 5.2.0 are affected. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and EPSS estimates only about a 0.9% probability of exploitation in the next 30 days, so no active exploitation is currently known.

Do: Check Fortinet's PSIRT advisory (CVE-2026-84387) for the fixed release and upgrade all FortiSandbox units off the affected versions (4.4.0-4.4.9, 5.0.0-5.0.6, and 5.2.0). Until patched, restrict high-privilege administrative access to the FortiSandbox management interface to trusted networks or VPN, since exploitation requires administrative credentials, and audit privileged accounts for unusual activity. Monitor appliance logs for unexpected commands, processes, or configuration changes.

7.2<1%
  • Fortinet FortiSandbox 5.2.0
  • Fortinet FortiSandbox 5.0.0 through 5.0.6
  • Fortinet FortiSandbox 4.4.0 through 4.4.9
moderate~1,000-10,000 deployed appliances (best estimate; only a subset are internet-exposed)