logo

Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator

ID: 72c30869-c82f-518d-b6ff-f4a8f4ee5146

STIX ID: report--72c30869-c82f-518d-b6ff-f4a8f4ee5146

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Sergiu Gatlan

...
...

Fortinet released patches for two critical vulnerabilities: CVE-2026-44277 (improper access control in FortiAuthenticator) and CVE-2026-26083 (missing authorization in FortiSandbox), both of which may allow unauthenticated remote code execution; FortiAuthenticator Cloud is not affected and Fortinet advises updating to the fixed versions, while noting the company’s products have been frequently targeted in past ransomware and espionage activity though these specific flaws are not reported as exploited in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.