Fortinet FortiSandbox authenticated RCE CVE-2026-84387 (CVSS 7.2) detailed by ZDI as Canadian Cyber Centre urges broad Fortinet patching via AV26-898
ZDI published ZDI-26-645 for CVE-2026-84387, an authenticated command injection RCE rated CVSS 7.2 in Fortinet FortiSandbox's write_remote_backup_to_crontab function, while the Canadian Centre for Cyber Security's advisory AV26-898 urged updates across…
On 2026-09-09 (2026-09-09T05:00:00Z), Zero Day Initiative published advisory ZDI-26-645 describing a command injection vulnerability in Fortinet FortiSandbox's write_remote_backup_to_crontab function, tracked as CVE-2026-84387. Remote authenticated attackers can execute arbitrary code through the cronValue parameter, and ZDI rated the issue CVSS 7.2. Separately, later the same day (2026-09-09T13:48:46Z), the Canadian Centre for Cyber Security issued advisory AV26-898 relaying Fortinet PSIRT advisories covering FortiOS 7.6.1-7.6.6, FortiProxy 7.6.2-7.6.6, FortiPAM Chrome extensions 7.4/8.0, FortiSandbox 4.4 and 5.0, FortiSandbox Cloud and PaaS 5.0.4-5.0.5, and FortiMonitorOnSight 7.2, and encouraging administrators and users to review the linked Fortinet advisories and apply the necessary updates. The two reports do not contradict each other, but they differ in specificity: the Canadian bulletin does not detail individual CVEs or exploitation and does not state whether it covers CVE-2026-84387, while only the ZDI report provides CVE identifiers, severity scoring and technical detail. No exploitation details, affected-version detail for the ZDI CVE, or patch status were stated in either report.
- ZDI advisory ZDI-26-645 (published 2026-09-09T05:00:00Z) describes a command injection RCE in Fortinet FortiSandbox's write_remote_backup_to_crontab function, exploitable by remote authenticated attackers via the cronValue parameter.
- The ZDI-tracked vulnerability is CVE-2026-84387, rated CVSS 7.2.
- Canadian Centre for Cyber Security advisory AV26-898 (published 2026-09-09T13:48:46Z) relays Fortinet PSIRT advisories and urges prompt patching.
- AV26-898 lists affected products/versions: FortiOS 7.6.1-7.6.6, FortiProxy 7.6.2-7.6.6, FortiPAM Chrome extensions 7.4/8.0, FortiSandbox 4.4 and 5.0, FortiSandbox Cloud and PaaS 5.0.4-5.0.5, and FortiMonitorOnSight 7.2.
- AV26-898 provides no specific CVE identifiers or exploitation details and directs users to the linked Fortinet advisories for update information.
- The Canadian bulletin covers FortiSandbox but does not tie its listed versions to any specific CVE, so it is not stated whether AV26-898 includes CVE-2026-84387.
- Both reports were published on 2026-09-09; neither states whether the vulnerabilities have been exploited in the wild.
Coverage timelineoldest first · each row is one article
- · 6d agoZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability
ZDI Published Advisories· 26
ZDI publishes ZDI-26-645 for CVE-2026-84387, an authenticated command injection RCE in Fortinet FortiSandbox via crontab backup, rated CVSS 7.2.
- · 6d agoFortinet security advisory (AV26-898)
Canadian Centre for Cyber Security· 26
Canadian Cyber Centre advisory AV26-898 flags Fortinet vulnerabilities across FortiOS, FortiProxy, FortiPAM, FortiSandbox and FortiMonitorOnSight, urging administrators to apply updates
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-84387 | High-Privilege Command Injection in Fortinet FortiSandbox CVE-2026-84387 is a command injection flaw (CWE-77) in Fortinet FortiSandbox in which special elements used in a command are not properly neutralized, allowing an attacker to inject and execute unauthorized commands or code on the appliance. The CVSS vector indicates the flaw is reachable over the network (AV:N) but requires the attacker to already hold high-privilege credentials (PR:H), such as an administrative account, with no user interaction required; the exact entry point in the product interface is not detailed in the available data. Successful exploitation carries high impact across confidentiality, integrity, and availability, effectively giving the attacker arbitrary command execution on a security appliance that handles untrusted analyzed files. All FortiSandbox deployments running versions 4.4.0 through 4.4.9, 5.0.0 through 5.0.6, or 5.2.0 are affected. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and EPSS estimates only about a 0.9% probability of exploitation in the next 30 days, so no active exploitation is currently known. Do: Check Fortinet's PSIRT advisory (CVE-2026-84387) for the fixed release and upgrade all FortiSandbox units off the affected versions (4.4.0-4.4.9, 5.0.0-5.0.6, and 5.2.0). Until patched, restrict high-privilege administrative access to the FortiSandbox management interface to trusted networks or VPN, since exploitation requires administrative credentials, and audit privileged accounts for unusual activity. Monitor appliance logs for unexpected commands, processes, or configuration changes. | 7.2 | <1% |
| moderate~1,000-10,000 deployed appliances (best estimate; only a subset are internet-exposed) |