FortiGuard Product Security Update Advisory

FortiGuard Product Security Update Advisory

Overview


A security update has been released to address vulnerabilities in FortiGuard products. Users of the affected products should update to the latest version.

Affected Products and Vulnerabilities


  • FortiAuthenticator.
    • CVE-2025-53379.
    • Affected versions: 6.5, 6.6.0 Through 6.6.2.
    • Vulnerability description: Out-of-bounds read vulnerability (a vulnerability that allows reading data outside the permitted range).
  • FortiSandbox.
    • CVE-2026-59835.
    • Affected versions: 4.4.3 Through 4.4.8, And 5.0.0 Through 5.0.2.
    • Vulnerability Description: Unauthorized access to the VNC server (an issue allowing access to the VNC server without authentication).

Resolution


Vulnerability Patches have been provided via the latest updates.

  • CVE-2025-53379: FortiAuthenticator 6.6.3 And later.
  • CVE-2026-59835: FortiSandbox 4.4.9 And later.
  • CVE-2026-59835: FortiSandbox 5.0.3 And later.

References


  • [1] Out-of-bounds read in GUI.
  • [2] Unauthenticated VNC access exposed on all interfaces.