VDB

CVE-2026-59835

CVE-2026-59835 PUBLISHED CVSS 7.7 HIGH

Reported by fortinet · Published July 14, 2026

A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.

Risk Scores

CVSS 3.1
7.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
FortinetFortiSandbox5.0.0, 4.4.3
FortinetFortiSandbox5.0.0, 4.4.3, 5.0.0

Timeline

  • Jul 14, 2026 Coalition ESS Score
  • Jul 14, 2026 CVE Published
  • Jul 15, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›