• News/
  • bleepingcomputer-20260512182309

Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator

BleepingComputer
·
Sergiu Gatlan
·
Published May 12, 2026
·
Updated

Fortinet has released security updates to address two critical vulnerabilities in FortiSandbox and FortiAuthenticator that could enable attackers to run commands or arbitrary code on unpatched systems. The first one, tracked as CVE-2026-44277, impacts the company's FortiAuthenticator Identity and Access Management (IAM) solution and was patched in FortiAuthenticator versions 6.5.7, 6.6.9, and 8.0.3. "An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests," Fortinet said in a Tuesday advisory. The company added that FortiAuthenticator Cloud (formerly known as FortiTrust Identity), an Identity and Access Management as a Service (IDaaS) cloud service hosted and managed by Fortinet, is not impacted by the issue. Today, Fortinet also addressed a missing authorization weakness (CVE-2026-26083) that can be exploited to achieve remote code execution on vulnerable FortiSandbox systems designed to protect against malicious activity, including zero-day threats. "A missing authorization vulnerability [CWE-862] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests," it added. While the company didn't tag these two security flaws as being exploited in the wild, Fortinet vulnerabilities are frequently exploited in ransomware and cyber-espionage attacks, often as zero-...

Read full article

Affected Software

4 affected components
Fortinet FortiAuthenticator=6.5.7, =6.6.9, =8.0.3
Fortinet FortiSandbox
Fortinet FortiSandbox Cloud
Fortinet FortiSandbox PaaS WEB UI
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities are addressed in the Fortinet security updates?

The updates address critical remote code execution (RCE) vulnerabilities in FortiSandbox and FortiAuthenticator.

2

What could happen if systems are not patched?

Unpatched systems may allow attackers to run commands or arbitrary code remotely.

3

Which versions of FortiAuthenticator are affected by these vulnerabilities?

Versions 6.5.7, 6.6.9, and 8.0.3 of FortiAuthenticator are affected.

4

What products from Fortinet are impacted by the security flaws?

The affected products include FortiSandbox, FortiAuthenticator, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI.

5

What action is recommended to mitigate these vulnerabilities?

Fortinet recommends applying the latest security updates to affected products immediately.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203