logo

Critical Fortinet vulnerabilities fixed in FortiSandbox and FortiAuthenticator

ID: d92c7739-529f-58d4-9acd-0c027df95c45

STIX ID: report--d92c7739-529f-58d4-9acd-0c027df95c45

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Pierluigi Paganini

...
...

Fortinet patched two critical unauthenticated remote code execution vulnerabilities—CVE-2026-44277 (FortiAuthenticator) and CVE-2026-26083 (FortiSandbox, including Cloud and PaaS WEB UI)—affecting multiple versions; administrators are advised to upgrade to fixed releases (e.g., FortiAuthenticator 8.0.3+/6.6.9+/6.5.7+). The flaws were found during an internal audit, reportedly have not been exploited in the wild, and were reported internally by Fortinet staff.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.