chiprook
← Security
SecuritySeptember 28, 2026, 10:20

CVE-2026-26084: FortiSandbox flaw leaks data without authentication

Fortinet disclosed CVE-2026-26084 (CWE-284, severity 8.9) in FortiSandbox: an unauthenticated attacker can send crafted HTTP requests via a specific NAT rule to read configuration and sample metadata. Affected versions are 4.4.0–4.4.8 and 5.0.0–5.0.5, fixed in 4.4.9 and 5.0.6. No exploitation in the wild has been observed.

CVE-2026-26084: FortiSandbox flaw leaks data without authentication
#Fortinet#FortiSandbox
Read next
Security

CVE-2026-17633: Authenticated RCE in Langflow OSS via /api/v1/custom_component

Security

Cisco ISE authentication bypass CVE-2026-76460: what defenders need to do now

Security

Cisco FMC authentication bypass CVE-2026-20079 has CVSS 10.0

Security

Patching Guide: Closing the CVE-2026-67276 SSH Authentication Bypass on MikroTik Routers