CVE-2026-26083Disclosure(fortinet / fortisandbox)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 13 mentions and remains active

Immediate actions

  • Patch fortinet fortisandbox systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiSandbox PaaS 21.4 all versions, FortiSandbox PaaS 21.3 all versions, FortiSandbox PaaS 5.0.0 through 5.0.1, FortiSandbox PaaS 4.4.5 through 4.4.8 may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortisandbox
  • fortisandbox_cloud
  • fortisandbox_paas

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 28 mentions across 7 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 14 signals
  • Technical details provided in 26 signals
  • Disclosure: 14 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 13 mentions (2026-05-13); latest day: 1
  • 28 total mentions across 7 days

Affected systems

Vendors
Products
fortisandboxfortisandbox_cloudfortisandbox_paas

1 version affected across 3 products

Deep dive

Activity timeline28 mentions / 7d
0371013Mentions · 2026-05-12: 7Mentions · 2026-05-13: 13Mentions · 2026-05-14: 2Mentions · 2026-05-18: 2Mentions · 2026-05-19: 2Mentions · 2026-07-30: 1Mentions · 2026-08-02: 1Active Exploitation · 2026-05-13: 2Patch / Workaround · 2026-05-12: 4Patch / Workaround · 2026-05-13: 4Patch / Workaround · 2026-05-14: 2Patch / Workaround · 2026-05-18: 2Patch / Workaround · 2026-05-19: 2Technical Details · 2026-05-12: 6Technical Details · 2026-05-13: 13Technical Details · 2026-05-14: 2Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 2Technical Details · 2026-07-30: 1Technical Details · 2026-08-02: 105-1205-1305-1405-1805-1907-3008-02
Signal classification4 categories
Disclosure
1450.0%
Patch
1035.7%
General
27.1%
Active Exploitation
27.1%
Referenced assets27 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-127
Disclosure4General1Patch2
2026-05-1313
Active Exploitation2Disclosure8Patch3
2026-05-142
Disclosure1Patch1
2026-05-182
Patch2
2026-05-192
Patch2
2026-07-301
General1
2026-08-021
Disclosure1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    Patch

    Urgent: Fortinet warns of 9.1 severity flaws in FortiSandbox (CVE-2026-26083) and FortiAuthenticator (CVE-2026-44277). Patch now to prevent unauthorized RCE. #Fortinet #FortiSandbox #FortiAuthenticator #CyberSecurity #InfoSec #VulnerabilityAlert #RCE https://securityonline.info/fortinet-critical-vulnerability-fortisandbox-fortiauthenticator-2026/ https://t.co/3bJN8TAfcD

    Post summary

    Fortinet issues an urgent patch alert for CVE-2026-26083 and CVE-2026-44277, noting 9.1 severity and RCE risk, and urging immediate remediation.

    04071610
    12.5K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    Fortinet、FortiSandboxとFortiAuthenticatorの重大なRCE脆弱性について警告(CVE-2026-44277、CVE-2026-26083) | Codebook https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45561/ "Fortinetはこれらの脆弱性が実際の攻撃で悪用されているとは述べていないが、同社製品の脆弱性はランサムウェア攻撃やサイバースパイ活動で…"

    Post summary

    The article announces two critical RCE vulnerabilities in Fortinet products but does not provide any PoC, exploit code, or evidence of active exploitation, nor does it mention patches or workarounds.

    10041434
    3.5K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    2026年5月ぱっちちゅーずでーまとめ ◆Microsoft https://www.microsoft.com/en-us/msrc/blog/2026/05/202605-security-update CVE-2026-42898 Microsoft Dynamics 365 オンプレミスのリモートでコードが実行される脆弱性 CVE-2026-42823 Azure Logic Apps の特権昇格の脆弱性 CVE-2026-41096 Windows DNS クライアントのリモートでコードが実行される脆弱性 CVE-2026-41089 Windows Netlogon のリモートでコードが実行される脆弱性 ◆Ivanti https://www.ivanti.com/blog/may-2026-security-update critical1件 ■CVE-2026-8043(Critical) ファイル名制御不備により認証済ユーザが任意ファイル読取・HTML書込可能。情報漏えいに加え、XSS等のクライアント攻撃や踏み台化の恐れ ◆Fortinet https://fortiguard.fortinet.com/psirt critical2件 ■CVE-2026-26083(FortiSandbox / 認証不要RCE) 認可不備により未認証攻撃者がHTTPリクエスト経由で任意コード実行可能。ネットワーク越し・認証不要で悪用可能なため侵害難易度が低く、最優先でのパッチ適用が必要。 ■CVE-2026-44277(FortiAuthenticator / 認証不要RCE) APIのアクセス制御不備により未認証攻撃者が任意コマンド実行可能。IAM基盤への侵害に直結し、認証・証明書管理を含む全体統制を破壊するリスクが高い。 ◆SAP SAP Security Patch Day - January 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/january-2026.html critical4件 ■ CVE-2026-0501(SQL Injection:S/4HANA) 外部入力の検証不備によりSQLインジェクションが成立し、DBの機密情報取得・改ざん・削除が可能。業務データへの直接影響が大きい。認証済ユーザ(業務ユーザ等)でも悪用可能なケースが想定され、権限逸脱型リスクが高い。 ■ CVE-2026-0500(RCE:Wily Introscope) 細工されたリクエストにより任意コード実行が可能となる脆弱性。監視基盤の乗っ取りや横展開の踏み台となる危険がある。認証不要または低権限でも悪用できる可能性があり、外部攻撃者・内部第三者双方に対して高リスク。 ■ CVE-2026-0498(Code Injection:S/4HANA) 入力処理不備を突いたコードインジェクションにより、アプリケーション処理の改ざんや不正実行が可能。業務アプリ経由で実行されるため、正規ユーザ(認証済第三者)による悪用や、意図しない権限範囲での操作に繋がるリスクが高い。 ■ CVE-2026-0491(Code Injection:Landscape Transformation) データ移行・統合処理におけるコードインジェクションにより、システム改ざんやデータ破壊が可能。移行作業や連携処理を扱う認証済ユーザから悪用される可能性があり、内部・委託先など第三者経由での被害拡大が懸念。 ◆Adobe https://helpx.adobe.com/security.html critical4件 ■CVE-2026-34659(Adobe Connect / RCE) デシリアライズ不備により未認証攻撃者が細工データを通じて任意コード実行可能。ユーザ操作誘導で成立し、CVSS9.6の極めて高リスク脆弱性。 ■CVE-2026-34660(Adobe Connect / 権限昇格) 認可不備により権限昇格が可能。RCEと組み合わせることで完全な環境乗っ取りに発展する恐れがあり、Connect系の中でも特に影響大。 ■CVE-2026-34653(Adobe Commerce / パストラバーサル) ディレクトリ操作不備により任意ファイル書込みが可能。攻撃者によるサーバ改ざん・Webシェル設置に繋がる恐れがある重大リスク。 ■CVE-2026-34686(Adobe Commerce / XSS→RCE) 保存型XSSにより任意スクリプト実行が可能。管理画面等と組み合わせるとコード実行やセッション奪取等の高リスク攻撃に発展。

    Post summary

    The post announces multiple critical CVEs across Microsoft, Ivanti, Fortinet, SAP, and Adobe, detailing their impact and vulnerability type.

    000211.4K
    11.7K followersView on X
  • Elusive@ElusivePrivacy
    Patch

    Fortinet Critical RCE Flaws Fortinet patches two critical RCE vulnerabilities in FortiSandbox (CVE-2026-44277, CVE-2026-26083) and FortiAuthenticator (CVE-2026-21643, CVE-2026-35616). Unauthenticated attackers can run arbitrary commands or code on affected appliances. No reports of active exploitation yet. Patch immediately. Source: BleepingComputer / Fortinet PSIRT Full analysis → http://t.me/VulnerabilityNews Follow @VulnerabilityNw

    Post summary

    Fortinet has released patches for four critical RCE vulnerabilities in FortiSandbox and FortiAuthenticator that allow unauthenticated command execution; no active exploitation has been reported, but users are urged to apply the fixes immediately.

    11010149
    172 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: 1 critical, 1 high, 3 medium vulnerabilities in #Fortinet #FortiOS #FortiSandbox #FortiAP #FortiAnalyzer #FortiManager #CVE-2026-26083 #CVE-2025-53844 #CVE-2025-53870 #CVE-2025-53680 #CVE-2025-67604 CVSS: 9.8-5.3 See: https://www.fortiguard.com/psirt & https://ccb.belgium.be/advisories/warning-multiple-critical-high-and-medium-vulnerabilities-fortinet-fortisandbox-fortios

    Post summary

    The tweet announces several critical, high, and medium‑severity vulnerabilities for Fortinet products, cites CVE IDs and CVSS scores, and directs readers to official advisories for patching.

    010101.6K
    7.2K followersView on X
  • Login Sécurité@LoginSecurite
    Disclosure

    🚨 Alertes sécurité : CVE-2026-26083 et CVE-2026-44277 sur FortiSandbox et FortiAuthenticator Des failles FortiSandbox et FortiAuthenticator permettent l'exécution de commandes à distance sans authentification. Plus d'informations : https://login-securite.com/alertes/fr-vulnerabilite-critique-dans-fortisandbox-et-fortiauthenticator

    Post summary

    The alert announces two new CVEs (CVE-2026-26083 and CVE-2026-44277) affecting FortiSandbox and FortiAuthenticator, describing them as critical remote command‑execution flaws requiring no authentication, without providing PoC, exploit code, or patch details.

    0002091
    553 followersView on X
  • Nullvy | CyberNews@NullvyNews
    Disclosure

    كشفت شركة فورتينت عن ثغرة أمنية حرجة في منصة FortiSandbox تحمل المعرف CVE-2026-26083، وتسمح للمهاجمين بتنفيذ أوامر أو شيفرات عن بُعد دون الحاجة إلى تسجيل دخول أو أي تفاعل من الضحية. 📌 للتفاصيل الكاملة: 🔗 https://www.instagram.com/p/DYRUXOoouRG/?igsh=MTc1c3JrMjcwajAwcA== #fortinet https://t.co/ogB8i28E6r

    Post summary

    The post announces a critical unauthenticated remote code execution vulnerability in FortiSandbox (CVE-2026-26083) that allows attackers to run commands without login, but does not provide PoC, active exploit evidence, or patch details.

    0002057
    22 followersView on X
  • Machina Record@MachinaRecord
    Disclosure

    🚨Fortinet、FortiSandboxとFortiAuthenticatorの重大なRCE脆弱性について警告(CVE-2026-44277、CVE-2026-26083) 🩹マイクロソフト、5月の月例パッチで脆弱性120件を修正 ゼロデイは含まれず(CVE-2026-35421、CVE-2026-40365他) 〜サイバーアラート5月13日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45561/

    Post summary

    Japanese cyber alert announces a critical RCE vulnerability in Fortinet products (CVE‑2026‑44277, CVE‑2026‑26083) and notes that Microsoft has patched 120 CVEs (including CVE‑2026‑35421 and CVE‑2026‑40365) as of May, with no zero‑day exploits reported.

    00020224
    1.3K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨FortiSandbox Missing Authorization RCE (CVE-2026-26083) A missing authorization vulnerability in Fortinet FortiSandbox allows an unauthenticated attacker to execute unauthorized code or commands via specially crafted HTTP requests. This critical flaw (CVSS 9.8) can lead to full system compromise, data theft, and remote code execution. 👉Affected: FortiSandbox 5.0.0-5.0.1, 4.4.0-4.4.8, FortiSandbox Cloud & PaaS (all listed versions)

    Post summary

    The text announces a new high‑severity CVE-2026-26083 vulnerability in FortiSandbox, detailing its nature and affected versions but providing no PoC, exploit code, or mitigation guidance.

    0002097
    187 followersView on X
  • iototsecnews@iototsecnews
    Patch

    FortiSandbox の脆弱性を CVE-2026-26083 が FIX:任意のコード/コマンド実行の恐れ https://iototsecnews.jp/2026/05/12/critical-fortinet-fortisandbox-vulnerability-enables-code-execution-attacks/ Fortinet のセキュリティ解析製品 FortiSandbox に見つかった、深刻な脆弱性について解説する記事です。 問題の原因は、管理用 Web 画面の設計において、利用者の権限を正しく確認する “認可チェック” が漏れていたことにあります。この欠陥を突く攻撃者は、認証を必要とせずに外部から自由にシステムを操作できる状態にありました。 脅威を検知する中核ツールが乗っ取られると、組織全体の防衛網が機能不全に陥る恐れがあります。実環境での悪用は確認されていませんが、 攻撃が容易で危険度が高いため、速やかなアップデートが強く推奨されます。 #CVE202626083 #Fortinet #FortiSandbox #Vulnerability

    Post summary

    The article discloses a severe FortiSandbox CVE involving a missing authorization check that could allow unauthenticated remote code execution; no active exploitation reported, but a prompt patch is strongly recommended.

    01000152
    489 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Fortinet 製品の脆弱性群が FIX:Critical な認可バイパスの脆弱性への対応が急務 https://iototsecnews.jp/2026/05/12/fortinet-patches-five-vulnerabilities-across-fortiap-fortios-and-enterprise-products/ 今回のセキュリティ・アドバイザリでは、認可の不備や入力値の検証不足が主な原因となっています。特に CVE-2026-26083 は、本来必要なはずの認可プロセスが欠落していたため、外部から認証なしで機密データに触れられてしまう状態でした。また CVE-2025-53680 や CVE-2025-53870 では、コマンド実行時の特殊文字に対する不適切な無効化が原因で、意図しない命令が実行されるリスクが生じています。ほかにも CVE-2025-67604 のように危険な関数の使用が原因となるものや、 CVE-2025-53844 のようにメモリへの書き込み範囲を正しく制限できていないケースも含まれています。ご利用のチームは、ご注意ください。#CVE202553680 #CVE202553844 #CVE202553870 #CVE202567604 #CVE202626083 #FortiAnalyzer #FortiAP #FortiManagerAPI #Fortinet #FortiOS #Vulnerability

    Post summary

    Fortinet issued a patch advisory for several critical vulnerabilities, detailing missing authorization and command‑execution flaws that allow unauthenticated access to sensitive data and execution of unintended commands. Immediate mitigation is recommended.

    01000158
    489 followersView on X
  • TodayInCyber@TodayInCyberIO
    Patch

    2/5 Ivanti Xtraction (CVE-2026-8043): a critical flaw enabling information disclosure and client-side attacks. Patch released. Fortinet FortiAuthenticator and FortiSandbox (CVE-2026-44277, CVE-2026-26083): critical vulnerabilities enabling remote code execution.

    Post summary

    The text announces critical vulnerabilities across three products, highlights that a patch is available for at least one of them, and provides brief technical details about the flaw types.

    100003
    8 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Fortinetが複数製品の脆弱性を修正、FortiSandboxの認可不備は未認証でコード実行の恐れ(CVE-2026-26083 他) https://rocket-boys.co.jp/security-measures-lab/fortinet-fortisandbox-rce-vulnerability-cve-2026-26083/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The article reports that Fortinet has released patches for several vulnerabilities, including CVE-2026-26083, which previously allowed unauthenticated code execution in FortiSandbox.

    01000146
    405 followersView on X
  • Jaden Johnson@JadenJohnsNews
    General

    🚨 CRITICAL Fortinet Alert Two critical vulnerabilities affecting Fortinet products could allow unauthenticated attackers to execute arbitrary code/commands via malicious requests: 🔴 CVE-2026-44277 — FortiAuthenticator 🔴 CVE-2026-26083 — FortiSandbox / FortiSandbox Cloud/PaaS https://t.co/3fb2dehrwE

    Post summary

    Fortinet announced two critical CVEs that permit unauthenticated attackers to execute arbitrary code via malicious requests, but no PoC, exploit code, patch, or active exploitation details are provided.

    00010764
    221 followersView on X
  • BREACHSPIDER@breachspider
    Disclosure

    [CVE Analysis] CVE-2026-26083: Missing Authorization in Fortinet FortiSandbox Exposes Malware Detonation Tier to Unauthenticated Command Execution https://breachspider.com/intel/2026-08-02-cve-2026-26083-missing-authorization-in-fortinet-fortisandbo #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The post reports a missing authorization flaw in Fortinet FortiSandbox that permits unauthenticated command execution on the Malware Detonation Tier.

    0000066
    2.3K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-26083: Fortinet FortiSandbox Missing Authorization Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04rm7490

    Post summary

    The title announces Fortinet FortiSandbox's missing authorization vulnerability (CVE-2026-26083) and signals business impact and response guidance, but lacks detailed technical info, PoC, or exploitation evidence.

    0000037
    32 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    Critical Missing Authorization Vulnerability has been discovered in #Fortinet's #FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS. Users are advised to follow OEM Security Advisories to remain safe! #CVE-2026-26083 https://www.fortiguard.com/psirt/FG-IR-26-136

    Post summary

    The tweet announces the discovery of a missing‑authorization flaw in Fortinet’s FortiSandbox products and advises users to apply vendor advisories, with no mention of PoC, exploit code, or active attacks.

    00000187
    8.4K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-26083 (Fortinet FortiSandbox) is a critical missing-authorisation flaw enabling unauthorised code/command execution via the web UI. See full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-05-12/TIER_2_CVE-2026-26083.md#CyberSecurity #DPI #Fortinet #ThreatDetection #VulnerabilityManagement

    Post summary

    The announcement describes a newly identified critical authorization flaw in Fortinet FortiSandbox that allows unauthorised code execution through the web UI, with no evidence of active exploitation or available fixes yet.

    0000065
    43 followersView on X
  • ohhara_P🧐Slow life in the isekai@ohhara_shiojiri
    Disclosure

    Fortinet、FortiSandboxとFortiAuthenticatorの重大なRCE脆弱性について警告(CVE-2026-44277、CVE-2026-26083) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45561/

    Post summary

    Fortinet products—including FortiSandbox and FortiAuthenticator—are affected by critical RCE vulnerabilities (CVE-2026-44277, CVE-2026-26083) as a recent warning highlights.

    0000078
    2.0K followersView on X
  • ByteCheck@ByteCheck101
    Patch

    @Fortinet warns of 2 critical RCE flaws CVE-2026-44277 (FortiAuthenticator): Unauthenticated RCE via improper access control. Fixed in 6.5.7 / 6.6.9 / 8.0.3 (Cloud not affected). CVE-2026-26083 (FortiSandbox): Missing authorization leading to RCE on WEB UI. Patch ASAP — Fortinet bugs get weaponized fast. #CyberSecurity #Fortinet

    Post summary

    Fortinet warns of two critical RCE vulnerabilities, provides specific patch versions, and urges users to apply updates immediately.

    0000048
    10 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortisandbox---
Appfortinetfortisandbox_cloud---
Appfortinetfortisandbox_cloud24.1.4436--
Appfortinetfortisandbox_paas---

Explore more