FORTINET Security Advisory

Published Date: July 14, 2026

Advisory Summary

🔔 Critical Security Alert: Unauthenticated VNC Access Vulnerability in FortiSandbox

Fortinet has identified a serious vulnerability (CWE-668) in its FortiSandbox solution that exposes all network interfaces to unauthenticated access via the VNC server running on virtual machines used in scanning operations. The flaw allows attackers to bypass authentication and gain control of VNC sessions by sending crafted network requests, posing significant risks to the integrity and confidentiality of scanned resources.

With a CVSSv3 base score of 7.7, this vulnerability demands immediate attention from IT infrastructure and security teams relying on FortiSandbox for threat detection. Exploitation could lead to unauthorized access to critical sandbox environments, potentially undermining malware analysis and threat prevention workflows.

This alert underscores the evolving risks in virtualized security environments and the importance of vigilant vulnerability management in data center infrastructure equipment.

Reference: Vendor Advisory