Fortinet Patches FortiOS Authentication Bypass and FortiSandbox Command Injection Flaws

Fortinet released a new batch of security advisories on July 14, 2026, addressing seven vulnerabilities spanning FortiOS, FortiProxy, FortiPAM, and FortiSandbox.

The disclosures range from low-severity header injection bugs to more consequential stack-based buffer overflows and an unauthenticated exposure flaw in FortiSandbox that could allow attackers to reach a management interface without credentials.

While none of the flaws in this round carry a Critical severity rating, several affect widely deployed products across multiple version branches, meaning the practical attack surface is broad.

Multiple Fortinet Flaws Patched

Enterprises running FortiOS 7.0 through 8.0, or FortiPAM and FortiProxy in similar version ranges, should treat this as a priority patch cycle.

The most notable issue is CVE-2026-59835, tracked as FG-IR-26-145, which stems from an Exposure of Resource to Wrong Sphere weakness (CWE-668) in FortiSandbox.

The bug exposes VNC access across all network interfaces without requiring authentication, effectively granting an unauthenticated attacker direct access to the sandbox’s remote console.

Given that FortiSandbox appliances often operate in security-sensitive detonation environments, this exposure could allow an attacker to pivot into internal analysis infrastructure.

Two stack-and-buffer overread issues round out the more technical risks. CVE-2025-43892 (FG-IR-26-154) is a buffer over-read (CWE-126) affecting FortiOS, FortiProxy, and FortiSASE, reachable via CLI by an authenticated user.

CVE-2026-59837 (FG-IR-26-148) is a stack-based buffer overflow (CWE-121) in the Log Report feature, exploitable through the GUI by an authenticated attacker, a class of bug that can lead to crashes or, in worse cases, code execution depending on memory layout protections.

CVE-2026-59839 (FG-IR-26-151) is a path traversal flaw (CWE-22) that allows an authenticated CLI user to delete files on the root file system, a dangerous primitive for denial-of-service or system sabotage, given how many product lines it touches (FortiOS, FortiPAM, FortiProxy across five-plus version branches each).

The remaining three bugs are lower-severity but still worth patching. CVE-2026-23573 (FG-IR-26-150) is a reflected XSS in the SSL-VPN portal, exploitable without authentication.

CVE-2025-62675 (FG-IR-26-152) and CVE-2025-62826 (FG-IR-26-153) are both HTTP response-splitting bugs (CRLF injection) in the Web Filter warning page and the captive portal authentication form, respectively, allowing unauthenticated attackers to inject headers into HTTP responses.

CVE IDVulnerability TypeAffected Products
CVE-2025-43892Buffer over-read (CWE-126)FortiOS 7.2–7.6, FortiProxy 7.2–7.6
CVE-2025-62675HTTP response splitting (CRLF injection)FortiOS 7.2–8.0, FortiProxy 7.2–7.6
CVE-2025-62826HTTP response splitting (CRLF injection)FortiOS 7.2–7.6, FortiProxy 7.2–7.6
CVE-2026-59839Path traversal (CWE-22)FortiOS 7.0–8.0, FortiPAM 1.4–1.8, FortiProxy 7.0–7.6
CVE-2026-23573Reflected XSS (SSL-VPN)FortiOS 7.2–8.0, FortiPAM 1.5–1.9, FortiProxy 7.2–7.6
CVE-2026-59837Stack-based buffer overflow (CWE-121)FortiOS 7.2–8.0, FortiPAM 1.5–1.9, FortiProxy 7.2–7.6
CVE-2026-59835Unauthenticated VNC exposure (CWE-668)FortiSandbox 4.4, 5.0, 5.2

Mitigation

According to Fortinet, administrators should upgrade to the fixed releases specified in each advisory (FG-IR-26-145 through FG-IR-26-154) without delay.

Where immediate patching isn’t feasible, organizations should restrict management interface and VNC access to trusted networks only, disable unnecessary CLI access for lower-privilege accounts, and monitor logs for anomalous authentication or file-deletion activity.

Given the CLI- and GUI-based authenticated bugs, enforcing strong access controls and multi-factor authentication on administrative accounts remains a critical compensating control.

Give your SOC the intelligence it needs to act with confidence.  
Explore ANY.RUN Threat Intelligence Feeds to reduce noise and improve operational efficiency. 

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories