Fortinet disclosed three high-severity security flaws affecting FortiMonitor, FortiSandbox, and FortiPAM today. These Fortinet vulnerabilities allow unauthorized access to sensitive corporate data and internal systems. Therefore, system administrators must apply software patches immediately to secure their network infrastructure.
- Product: Fortinet FortiSandbox PaaS
- Vulnerabilities: 1 flaw (CVE-2026-26084)
- Highest severity: 9.9 (Critical · CVSSv3)
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-26084 | 9.9 | CWE-284 | Not exploited |
Why This Matters
Fortinet products protect thousands of enterprise networks globally. Consequently, unpatched Fortinet vulnerabilities expose these organizations to data breaches and total system compromise. According to the FortiPAM extension disclosure, attackers can intercept highly sensitive internal communications. This specific flaw “may allow a remote unauthenticated attacker to proxy a user’s browser traffic through attacker controlled servers if the user visits a malicious website.” Such access severely threatens organizational security.
How the Attack Works
The first flaw involves a static key issue in FortiMonitor OnSight. As detailed in the FortiMonitor security advisory, attackers bypass authentication “via forged or reused JWT.” Second, an improper access control bug impacts FortiSandbox. Specifically, attackers submit crafted HTTP requests to manipulate network rules and expose data. Finally, a malicious website can trigger the FortiPAM vulnerability. This action routes user traffic directly through attacker servers.
Affected Versions
The FortiMonitor vulnerability impacts versions 7.2.0 through 7.2.7. Meanwhile, the FortiSandbox bug affects 4.4 and 5.0 versions across local and cloud deployments. Finally, the FortiPAM extension issue compromises all 7.4 and 8.0 releases. Precise affected installation counts remain unavailable at this time.
Patch and Mitigation Steps
Currently, no public proof-of-concept exploits exist. Furthermore, researchers have not confirmed any active exploitation in the wild. Administrators must upgrade FortiMonitor to version 7.2.8. Similarly, users should update FortiSandbox components to versions 4.4.9 or 5.0.6. For FortiPAM protection, customers must update their server software and upgrade the Chrome extension to version 8.0.1.123 or higher. Vulnerability remediation requires coordinated updates across multiple components. Network defenders must prioritize these updates immediately.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!