Do you use Fortinet devices? Several security vulnerabilities have been patched in FortiOS, FortiProxy, FortiPAM, and FortiSandbox!

Imported from official source

Announcement

On July 14, 2026, Fortinet released official security advisories regarding seven new security vulnerabilities identified in its core security products — FortiOS, FortiProxy, FortiPAM, and FortiSandbox.

The discovered vulnerabilities include Path Traversal, Buffer Overflow, Cross-Site Scripting (XSS), CRLF Injection, as well as unauthenticated access to the VNC service. Although none of them have been rated as “Critical,” some affect security devices widely deployed in corporate networks, which is why experts strongly recommend applying updates as soon as possible.

The vulnerabilities have been identified in the following Fortinet products and versions:

These products perform critical functions such as protecting corporate networks, controlling internet traffic, managing privileged accounts, and analyzing suspicious files in an isolated environment. Therefore, any vulnerability in them can have a negative impact on overall network security.

The vulnerabilities announced by Fortinet include:

  • CVE-2025-43892 — Buffer Over-read vulnerability triggered through an authenticated user;
  • CVE-2025-62675 — CRLF Injection (HTTP Response Splitting) on the Web Filter warning page;
  • CVE-2025-62826 — CRLF Injection on the Captive Portal authentication page;
  • CVE-2026-59839 — Path Traversal vulnerability via the CLI;
  • CVE-2026-23573 — Reflected Cross-Site Scripting (XSS) on the SSL-VPN portal;
  • CVE-2026-59837 — Stack-based Buffer Overflow during log report generation;
  • CVE-2026-59835 — Unauthenticated VNC service exposed on all network interfaces on FortiSandbox devices.
  • Which vulnerabilities are the most dangerous?

    According to experts, two cases among the announced vulnerabilities require particular attention.

    CVE-2026-59835 — Unauthenticated VNC in FortiSandbox

    This vulnerability is related to the Virtual Network Computing (VNC) service on FortiSandbox devices being accessible without authentication on all network interfaces.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://uzcert.uz/en/do-you-use-fortinet-devices-several-security-vulnerabilities-have-been-patched-in-fortios-fortiproxy-fortipam-and-fortisandbox/

    Officially imported this from UZCERT’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    UZCERT — imported from official source
    Official source
    https://uzcert.uz/en/feed/ RSS
    Imported
    October 03, 2026 20:40
    Versions
    1 recorded
    Identity
    https://uzcert.uz/?p=39202

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.