Fortinet FortiAuthenticator vulnerability: Find affected assets
ID: 93951efb-4fb8-52f0-a35e-aec240b47eef
STIX ID: report--93951efb-4fb8-52f0-a35e-aec240b47eef
Feed Name: runZero Blog
Threat Score
Fortinet disclosed CVE-2026-44277, a critical (CVSS 9.1) improper access control vulnerability in FortiAuthenticator that may allow unauthenticated, remote attackers to gain unauthorized API access and execute commands or code; affected versions include FortiAuthenticator 8.0.0 and 8.0.2, 6.6.0–6.6.8, and 6.5.0–6.5.6, and Fortinet advises upgrading to 8.0.3, 6.6.9, or 6.5.7 (or later) to remediate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
