Fortinet patches CVE-2026-26084 in FortiSandbox
Fortinet issued FG-IR-26-166 for CVE-2026-26084, an 8.9 FortiSandbox flaw that can expose sensitive information.
Fortinet issued advisory FG-IR-26-166 for CVE-2026-26084 in the FortiSandbox web interface, an 8.9 flaw affecting FortiSandbox Cloud, FortiSandbox PaaS, and on-premises deployments. The issue lets an unauthenticated attacker send crafted HTTP requests to access configurations and logs.
Update September 19, 2026: Fortinet released advisory FG-IR-26-166 for CVE-2026-26084, an access-control flaw in FortiSandbox that can expose information. CISA included it in its weekly summary for the week of September 7, and Fortinet said there is no evidence of active exploitation.
Fortinet, Commvault and Microsoft were all in focus in the CISC bulletin published on September 8, 2026. The roundup was meant to guide mitigation and risk prioritization in Brazil. It included Fortinet cloud services, Commvault Cloud, and Microsoft’s September patch cycle, which delivered about 970 fixes and several issues tied to identity and cloud services.
What did the Brazilian bulletin include?
The CISC bulletin gathered vulnerabilities from international vendors affecting both cloud services and hybrid environments. In Fortinet’s case, the international advisories aligned to the same time window point to FortiSandbox Cloud 5.0 and FortiSandbox PaaS 5.0, in versions 5.0.4 through 5.0.5. For Commvault Cloud, the Canadian advisory detailed affected version ranges in the 11.36, 11.40, 11.44, and 11.46 branches, earlier than specific builds.
What changed in Fortinet’s case?
Fortinet published advisory FG-IR-26-166 on September 8, 2026, about CVE-2026-26084 in the FortiSandbox web interface. The flaw has a CVSS score of 8.9 and is classified as a CWE-284 access-control issue. It affects both on-premises installations and the FortiSandbox Cloud and FortiSandbox PaaS services.
CVE-2026-26084 allows a remote, unauthenticated attacker to send specially crafted HTTP requests to the shared FortiSandbox GUI and access sensitive information, including configurations and logs. The described impact is information exposure, not code execution.
Affected versions include FortiSandbox 4.4.0 through 4.4.8 and 5.0.0 through 5.0.5, as well as FortiSandbox Cloud 5.0.4 through 5.0.5 and FortiSandbox PaaS 5.0.4 through 5.0.5. The fix arrives in 4.4.9 and 5.0.6, while the 5.2 branch and certain cloud builds are not affected.
| Element | Scope or technical detail | Source or agency |
|---|---|---|
| FortiSandbox | 4.4.0 through 4.4.8 and 5.0.0 through 5.0.5 affected | Fortinet, ZeroHour |
| FortiSandbox Cloud 5.0 | 5.0.4 through 5.0.5 affected | Fortinet, ZeroHour |
| FortiSandbox PaaS 5.0 | 5.0.4 through 5.0.5 affected | Fortinet, ZeroHour |
| Fix | 4.4.9 and 5.0.6 | Fortinet |
| Severity | CVSS 8.9 | Fortinet, CISA |
CISA added CVE-2026-26084 to its weekly vulnerability summary for the week of September 7, 2026. The U.S. agency kept the description of sensitive information access through manipulated HTTP requests and the 8.9 severity score.
Fortinet said its internal Product Security team discovered the flaw and credited Adham El Karn. The company also said that, at the time of the advisory, it had no evidence of real-world exploitation.
Why does cloud remain the focus?
Because the flaws are not limited to local appliances, they also affect services used by organizations in cloud and multi-tenant setups. According to the Canadian Centre for Cyber Security, Fortinet’s vulnerabilities broaden the risk surface into cloud components. In Microsoft’s case, technical analysis of the September 8 cycle said several of the highest-priority vulnerabilities were tied to cloud identity and associated services before public disclosure.
What does Microsoft’s September cycle show?
It shows an unusually large patch window, with around 970 vulnerabilities fixed on September 8, 2026, according to the research sources cited in the material. That set included critical flaws in identity and cloud services affecting global tenants. Independent analysis described the same cycle as a two-track release, with the most sensitive risk concentrated in cloud components.
| Element | Scope or technical detail | Source or agency |
|---|---|---|
| FortiSandbox Cloud 5.0 | Versions 5.0.4 through 5.0.5 affected | Canadian Centre for Cyber Security, Fortinet |
| FortiSandbox PaaS 5.0 | Versions 5.0.4 through 5.0.5 affected | Canadian Centre for Cyber Security, Fortinet |
| Commvault Cloud | 11.36, 11.40, 11.44 and 11.46 branches, earlier than specific builds | Canadian Centre for Cyber Security, Commvault |
| Microsoft Patch Tuesday | About 970 vulnerabilities fixed on September 8, 2026 | Shattered.io, Igor's Lab, Qore |
How urgent is the prioritization?
The same set of vulnerabilities from the September 8 and 9, 2026 window fed known-exploited vulnerability catalogs and mandatory patching orders for federal agencies in other countries. The cited material mentions critical flaws in artifact platforms, remote access, and routers, all common components in hybrid and cloud infrastructure. At the same time, private security firms in Brazil described the cycle as marked by active attacks against Microsoft, VMware and SAP Commerce Cloud, including a remote code execution flaw in the latter service.
Independent technical bulletins and weekly cybersecurity newsletters placed the FortiSandbox vulnerability, including Cloud and PaaS, among the high-impact flaws of the second week of September 2026. The same coverage listed it alongside a Microsoft zero-day and critical bugs in other products, reinforcing its priority in global cloud patch management programs.
Third-party technical content and blogs also described an additional cluster of critical FortiSandbox vulnerabilities during September 2026, including CVE-2026-39808, CVE-2026-25089 and CVE-2026-26083, linked to remote code execution and confirmed active exploitation. That front increased operational risk for environments combining on-premises FortiSandbox with deployments integrated into public clouds.
What about the rest of September’s cycle?
Recommendations from Asian players such as AhnLab for the September 2026 patch cycle listed multiple Microsoft update waves, from September 3 through September 17, and stressed the need to fold Patch Tuesday and out-of-cycle releases into unified security management for Azure and Microsoft 365 services in corporate cloud environments. Later technical coverage also pointed to critical patches in Azure Database for PostgreSQL and other managed cloud services, with references to national CERT advisories such as Paraguay’s.
Sources
- Boletim do CISC de Vulnerabilidadesgov.br· gov.br / CISC
- Bulletin de sécurité Fortinet (AV26-898)cyber.gc.ca· Centre canadien pour la cybersécurité
- Microsoft's Two-Track Patch Tuesday: Cloud Identity Flaws Fixed Before Disclosure, Windows Still Catching Uptech.yahoo.com· Yahoo Tech
- VECTR-CAST: 14-Day Cyber Threat Forecast for U.S. Organizationscyberwarrior76.substack.com· Cyberwarrior76 (Substack)
- U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalogsecurityaffairs.com· Security Affairs
- Microsoft Patch Tuesday: 974 Bugs, 2 Zero-Days [2026]shattered.io· Shattered.io
- Microsoft corrige hasta 997 fallas de seguridadqore.com· Qore
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect ...thehackernews.com· The Hacker News
- Microsoft patches 966 vulnerabilities: Two Windows zero-days ...igorslab.de· Igor's Lab
- Bulletin de sécurité Commvault (AV26-899)cyber.gc.ca· Centre canadien pour la cybersécurité
- Redbelt Security aponta ataques contra Microsoft e VMwareitsection.com.br· Itsection
- Vulnerability Summary for the Week of September 7, 2026 – includes CVE-2026-26084content.govdelivery.com· CISA
- Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and morecybersecuritynews.com· Cyber Security News
- September 2026 News & Updates (a new record) – FortiSandbox critical RCE setctc.co· CTC Security Blog
- Microsoft Fixes Critical Azure, Microsoft 365 and Copilot Privilege Issues – includes CERT-PY referencemallory.ai· Mallory Security Intelligence
- Weekly Cybersecurity Newsletter – Top 50 Biggest Cyber Stories of September 7–12, 2026gbhackers.com· GBHackers on Security
- Fortinet disclosed CVE-2026-26084 (advisory FG-IR-26-166)zerohour.day· ZeroHour
- Fortinet (Vendor): news timeline & CVEs – FortiSandbox Cloud/PaaS impactzerohour.day· ZeroHour
- Recommendations for the September 2026 Regular Microsoft Patch Cycleasec.ahnlab.com· AhnLab ASEC



