cbcvebase.
CVE-2026-59835
published 2026-07-14

CVE-2026-59835: A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an…

PriorityP263high8.6CVSS 3.1
AVNACLPRNUINSUCHILAL
EPSS
0.42%
34.2th percentile
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.

Affected

6 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortisandbox
fortinetfortisandbox>= 4.4.3 < 4.4.94.4.9
fortinetfortisandbox4.4.3 – 4.4.8
fortinetfortisandbox>= 5.0.0 < 5.0.35.0.3
fortinetfortisandbox5.0.0 – 5.0.2

Detection & IOCsextracted from sources · hover to see the quote

  • Unauthenticated network requests targeting VNC server ports of FortiSandbox scanning VMs should be monitored; the vulnerability exposes VNC servers on all interfaces to unauthenticated attackers.
  • Alert on unauthenticated VNC access attempts originating from external/untrusted network segments directed at FortiSandbox appliances running versions 5.0.0–5.0.2 or 4.4.3–4.4.8.
  • ·The VNC server of scanning VMs is exposed on ALL network interfaces, not restricted to management or loopback — review firewall/ACL rules to confirm VNC ports are not reachable from untrusted networks on affected FortiSandbox versions.
  • ·Affected versions are FortiSandbox 5.0.0 through 5.0.2 and FortiSandbox 4.4.3 through 4.4.8; verify deployed version falls outside these ranges after patching.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.