# CVE-2026-59835

## Summary

- **CVE ID:** CVE-2026-59835
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L/E:P/RL:O/RC:C)
- **CWE:** CWE-668
- **Published:** Jul 14, 2026
- **Last Modified:** Jul 16, 2026

## Description

A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.

## Affected Products

- Fortinet — FortiSandbox (5.0.0)
- Fortinet — FortiSandbox (4.4.3)

## References

- [CNA](https://fortiguard.fortinet.com/psirt/FG-IR-26-145)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.40%
- **EPSS Percentile:** 33.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._