CVE-2026-59835
published 2026-07-14CVE-2026-59835: A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an…
PriorityP263high8.6CVSS 3.1
AVNACLPRNUINSUCHILAL
EPSS
0.42%
34.2th percentile
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | >= 4.4.3 < 4.4.9 | 4.4.9 |
| fortinet | fortisandbox | 4.4.3 – 4.4.8 | — |
| fortinet | fortisandbox | >= 5.0.0 < 5.0.3 | 5.0.3 |
| fortinet | fortisandbox | 5.0.0 – 5.0.2 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Unauthenticated network requests targeting VNC server ports of FortiSandbox scanning VMs should be monitored; the vulnerability exposes VNC servers on all interfaces to unauthenticated attackers. ↗
- →Alert on unauthenticated VNC access attempts originating from external/untrusted network segments directed at FortiSandbox appliances running versions 5.0.0–5.0.2 or 4.4.3–4.4.8. ↗
- ·The VNC server of scanning VMs is exposed on ALL network interfaces, not restricted to management or loopback — review firewall/ACL rules to confirm VNC ports are not reachable from untrusted networks on affected FortiSandbox versions. ↗
- ·Affected versions are FortiSandbox 5.0.0 through 5.0.2 and FortiSandbox 4.4.3 through 4.4.8; verify deployed version falls outside these ranges after patching. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Unauthenticated VNC access exposed on all interfaces
vendor_fortinet·2026-07-14·CVSS 8.6
CVE-2026-59835 [HIGH] CWE-668 Unauthenticated VNC access exposed on all interfaces
FG-IR-26-145: Unauthenticated VNC access exposed on all interfaces
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
CVEs: CVE-2026-59835
CWEs: CWE-668
CVSS: 8.6 (high)
Affected products: FortiSandbox, Fortinet
GHSA
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VM
ghsa_unreviewed·2026-07-14
CVE-2026-59835 [HIGH] CWE-668 A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VM
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-14
Published