FORTINET has disclosed three high-severity vulnerabilities affecting FortiMonitor OnSight, FortiSandbox, and FortiPAM, potentially allowing unauthorized access to sensitive corporate data and internal systems. The FortiMonitor flaw involves a static key issue that lets attackers bypass authentication via forged or reused JWTs.
FortiSandbox suffers from improper access control enabling manipulation of network rules through crafted HTTP requests, while FortiPAM can be triggered via a malicious website to route user traffic through attacker-controlled servers. Fortinet notes that there is no confirmed exploitation in the wild at present, but the implications are significant for organisations relying on these products.
Affected versions and patches are as follows: FortiMonitor is impacted from 7.2.0 through 7.2.7 and should be upgraded to 7.2.8. FortiSandbox has vulnerable 4.4 and 5.0 releases across local and cloud deployments, with updates to 4.4.9 or 5.0.6 recommended. FortiPAM affects all 7.4 and 8.0 releases; users should update their server software and the Chrome extension to version 8.0.1[.]123 or higher.
Fortinet characterises the CVE for FortiMonitor as CVE-2026-26084 with a CVSSv3 score of 9.9 (CWE-284) and states that FortiPAM’s extension issue requires coordinated updates across multiple components. Administrators are urged to apply patches promptly to mitigate the risk of data breaches and potential full system compromise.