logo

Fortinet FortiAuthenticator vulnerability: Find affected assets

ID: 93951efb-4fb8-52f0-a35e-aec240b47eef

STIX ID: report--93951efb-4fb8-52f0-a35e-aec240b47eef

Feed Name: runZero Blog

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: runZero Team

...
...

Fortinet disclosed CVE-2026-44277, a critical (CVSS 9.1) improper access control vulnerability in FortiAuthenticator that may allow unauthenticated, remote attackers to gain unauthorized API access and execute commands or code; affected versions include FortiAuthenticator 8.0.0 and 8.0.2, 6.6.0–6.6.8, and 6.5.0–6.5.6, and Fortinet advises upgrading to 8.0.3, 6.6.9, or 6.5.7 (or later) to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.