Fortinet Critical Alert: 9.1 Severity Flaws in FortiSandbox and FortiAuthenticator Risk Remote Takeover
ID: aca73f64-96fd-5934-9e28-b24570428de0
STIX ID: report--aca73f64-96fd-5934-9e28-b24570428de0
Feed Name: securityonline.info
Threat Score
Fortinet disclosed two critical vulnerabilities (CVE-2026-26083 and CVE-2026-44277) affecting FortiSandbox and FortiAuthenticator; both carry CVSS 9.1 and allow unauthenticated attackers to send crafted HTTP requests that may execute unauthorized code or commands. The advisory lists affected version ranges and remediation upgrade paths (specific patched versions and migrations) and notes FortiAuthenticator Cloud is not impacted by CVE-2026-44277.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
