Fortinet Security Updates – 15 July 2026

Fortinet has released a security update to address several vulnerabilities affecting multiple Fortinet products.

The addressed vulnerabilities could allow the attackers to obtain sensitive information, gain elevated privileges, or execute unauthorized code or commands on the affected systems.

Sample of the addressed vulnerabilities:

1. Fortinet FortiSandbox Unauthenticated VNC Access Vulnerability (CVE-2026-59835):

  • CVSS: 7.7
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Obtain Information

2. Fortinet FortiSIEM Improper Restriction Of Communication Channel To Intended Endpoints (CVE-2026-59841):

  • CVSS: 6.9
  • Attack Vector: Adjacent
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Privileges

The affected products:

  • FortiSandbox.
  • FortiSIEMWindowsAgent.
  • FortiAuthenticator.
  • FortiOS.
  • FortiPAM.
  • FortiProxy.
  • FortiClientEMS.
  • FortiSIEM.
Vulnerabilities
  • CVE-2025-43892
  • CVE-2025-53379
  • CVE-2025-62675
  • CVE-2025-62826
  • CVE-2026-23573
  • CVE-2026-59835
  • CVE-2026-59836
  • CVE-2026-59837
  • CVE-2026-59838
  • CVE-2026-59839
  • CVE-2026-59840
  • CVE-2026-59841
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Fortinet Security Advisory

References