Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator
ID: 72c30869-c82f-518d-b6ff-f4a8f4ee5146
STIX ID: report--72c30869-c82f-518d-b6ff-f4a8f4ee5146
Feed Name: Bleeping Computer
Fortinet released patches for two critical vulnerabilities: CVE-2026-44277 (improper access control in FortiAuthenticator) and CVE-2026-26083 (missing authorization in FortiSandbox), both of which may allow unauthenticated remote code execution; FortiAuthenticator Cloud is not affected and Fortinet advises updating to the fixed versions, while noting the company’s products have been frequently targeted in past ransomware and espionage activity though these specific flaws are not reported as exploited in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
