FortiGuard Product Security Update Advisory
Overview
A security update has been released to address vulnerabilities in FortiGuard products. Users of the affected products should update to the latest version.
Affected Products and Vulnerabilities
- FortiAuthenticator.
- CVE-2025-53379.
- Affected versions: 6.5, 6.6.0 Through 6.6.2.
- Vulnerability description: Out-of-bounds read vulnerability (a vulnerability that allows reading data outside the permitted range).
- FortiSandbox.
- CVE-2026-59835.
- Affected versions: 4.4.3 Through 4.4.8, And 5.0.0 Through 5.0.2.
- Vulnerability Description: Unauthorized access to the VNC server (an issue allowing access to the VNC server without authentication).
Resolution
Vulnerability Patches have been provided via the latest updates.
- CVE-2025-53379: FortiAuthenticator 6.6.3 And later.
- CVE-2026-59835: FortiSandbox 4.4.9 And later.
- CVE-2026-59835: FortiSandbox 5.0.3 And later.
References
- [1] Out-of-bounds read in GUI.
- [2] Unauthenticated VNC access exposed on all interfaces.