FortiSandbox Cron Job Injection in Remote Backup
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 6.7, CVEs: CVE-2026-84387, Summary: An Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability [CWE-77] in FortiSandbox may allow a privileged attacker to execute unauthorized code or commands via crafted HTTP requests.
CVSS 6.7 CVE-2026-84387 Fortinet FI