

Multiple Fortinet products are affected including FortiOS (versions 7.2 through 7.6), FortiProxy (versions 7.2 through 7.6), FortiPAM (versions 1.0 through 1.8), FortiSandbox (versions 4.4.3 through 5.0.2), and FortiSwitch Manager. The specific affected and fixed versions vary per CVE.
Fortinet published seven advisories on 15 July 2026 covering vulnerabilities across its security product portfolio. The highest severity issue, CVE-2026-59835 (CVSS 7.7), allows an unauthenticated attacker to access the VNC server of virtual machines being scanned by FortiSandbox, potentially exposing sensitive content under analysis. Additional vulnerabilities include stored XSS enabling code execution via the Agentless SSL-VPN interface, path traversal allowing privileged attackers with physical access to delete the file system, a stack-based buffer overflow enabling arbitrary code execution, and HTTP response splitting vulnerabilities in the web filter and captive portal.
Advisories published 15 July 2026. No active exploitation confirmed at time of publication. Fixed versions are available across all affected product lines. Organisations running affected FortiOS, FortiProxy, FortiPAM, or FortiSandbox versions should apply updates within the standard ten-working-day remediation window, with priority on CVE-2026-59835 and CVE-2026-23573 given their unauthenticated or low-privilege attack vectors.
CVE-2026-59835 is exploitable by unauthenticated network attackers against FortiSandbox deployments. CVE-2026-23573 requires an authenticated user but is reachable via the Agentless SSL-VPN interface. CVE-2026-59839 requires physical access. CVE-2026-59837 requires a privileged authenticated attacker capable of bypassing stack protections. The buffer over-read and HTTP response splitting issues require authentication or specific token possession.
CVE-2026-59835 exposes VNC sessions of virtual machines being scanned by FortiSandbox to unauthenticated network attackers, potentially allowing them to observe or interact with sensitive files and processes under analysis. CVE-2026-23573 allows authenticated SSL-VPN users to inject and execute arbitrary code via crafted requests. CVE-2026-59839 allows a privileged attacker with physical device access to delete the file system via path traversal in CLI commands, resulting in full device destruction. CVE-2026-59837 enables a privileged attacker who can bypass stack protections to execute arbitrary code. The HTTP response splitting issues (CVE-2025-62675, CVE-2025-62826) and buffer over-read (CVE-2025-43892, CVE-2026-59840) represent lower-severity information leakage and header injection risks.
Risk is rated High for large and medium government and business entities, and Medium for small entities. Fortinet products are pervasive across enterprise network security infrastructure. CVE-2026-59835 is particularly notable in environments where FortiSandbox is used to analyse sensitive or confidential documents, as unauthenticated VNC access could expose that content. The XSS code execution vulnerability in Agentless SSL-VPN is a meaningful risk in any environment where FortiOS SSL-VPN is internet-exposed.
Apply Fortinet stable channel updates to the following fixed versions:
CVE-2026-59835 (FortiSandbox): Upgrade 5.0.x to 5.0.3 or above; upgrade 4.4.x to 4.4.9 or above.
CVE-2026-23573 (FortiOS XSS): Upgrade FortiOS 7.6.x to 7.6.7 or above; upgrade FortiProxy 7.2.x to 7.2.10 or above, 7.4.x to 7.4.4 or above.
CVE-2026-59839 (Path Traversal): Upgrade FortiOS 7.4.x to 7.4.10 or above; upgrade FortiProxy 7.4.x to 7.4.14 or above; upgrade FortiPAM 1.8 to 1.8.1 or above.
CVE-2026-59837 (Stack Overflow): Upgrade FortiOS 7.4.x to 7.4.2 or above; upgrade FortiProxy 7.4.x to 7.4.14 or above; upgrade FortiPAM 1.8.x to 1.8.3 or above.
CVE-2025-43892 / CVE-2026-59840 (Buffer Over-Read): Upgrade FortiOS 7.6.x to 7.6.4 or above, 7.4.x to 7.4.9 or above; upgrade FortiProxy 7.6.x to 7.6.6 or above, 7.4.x to 7.4.14 or above.
CVE-2025-62675 / CVE-2025-62826 (HTTP Response Splitting): Upgrade FortiOS 7.6.x to 7.6.5 or above; upgrade FortiProxy 7.6.x to 7.6.5 or above. FortiOS 7.4 and 7.2 users must migrate to a fixed release.
Apply the Principle of Least Privilege across all Fortinet administrative accounts. Implement network segmentation to restrict access to FortiSandbox VNC and management interfaces. Conduct automated vulnerability scans of externally-exposed assets monthly. Review SSL-VPN access logs for anomalous authenticated sessions or unexpected code execution indicators. Ensure anti-exploitation features are enabled across FortiOS and FortiPAM deployments where supported.
Fortinet PSIRT Advisories: FG-IR-26-154, FG-IR-26-152, FG-IR-26-153, FG-IR-26-151, FG-IR-26-150, FG-IR-26-148, FG-IR-26-145. CVEs: CVE-2025-43892, CVE-2026-59840, CVE-2025-62675, CVE-2025-62826, CVE-2026-59839, CVE-2026-23573, CVE-2026-59837, CVE-2026-59835.
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




