HomeUpdatesFortinet fixes critical RCEs in FortiAuthenticator and FortiSandbox

Fortinet patches critical RCEs in FortiAuthenticator and FortiSandbox

Fortinet has released a series of security updates for its products, fixing, among other things, two critical vulnerabilities that could lead to remote code execution . Fortinet vulnerabilities, whether zero-day or n-day, have been exploited many times in the past, so companies should apply the updates as soon as possible.

Fortinet FortiAuthenticator and FortiSandbox

“ Fortinet vulnerabilities are often attractive to malicious users because these products are located in high-trust functions that attackers often target ,” Piyush Sharma , CEO and co-founder of SecOps firm Tuskira, told CSO . “ When a vulnerability affects a tool that already has privileged visibility or is close to critical systems, exploitation can give attackers a much greater head start than a vulnerability in a common application .”

See also: MDASH: Microsoft's new AI system finds 16 vulnerabilities in Windows

Fortinet: FortiAuthenticator Vulnerability

The vulnerability in FortiAuthenticator, codenamed CVE-2026-44277, has a CVSS score of 9.1 and is described as an improper access control. Successful exploitation allows unauthenticated attackers to execute unauthorized code and commands by sending specially crafted requests.

FortiAuthenticator, an identity and access management (IAM) solution, acts as a central hub for RADIUS, LDAP, and SAML authentication . It integrates with Active Directory and supports single sign-on and multi-factor authentication .

To fix this new vulnerability, companies are urged to upgrade to FortiAuthenticator 6.5.7, 6.6.9 or 8.0.3 depending on the version they are using.

Fortinet patches critical RCEs in FortiAuthenticator and FortiSandbox

Fortinet: FortiSandbox vulnerability

The FortiSandbox vulnerability is an authorization that also allows unauthenticated attackers to execute arbitrary code and commands via HTTP requests. Codenamed CVE-2026-26083, the vulnerability also has a CVSS score of 9.1.

See also: New Exim BDAT vulnerability exposes GnuTLS constructs

FortiSandbox is a threat detectiondesigned to identify zero-day threats using machine learning to perform static and dynamic analysis on suspicious files within an isolated environment. It integrates with other Fortinet security products such as FortiGate and FortiMail and is available in various versions, including hardware and virtual appliances.

The vulnerability affects all supported versions of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. Users are advised to upgrade to version 4.4.9 or 5.0.2, depending on the version.

Fortinet vulnerability exploitation

CVE-2026-26083 and CVE-2026-44277 were discovered internally by Fortinet and there is currently no evidence of exploitation. However, exploits for other Fortinet RCE vulnerabilities have been used by attackers in the past.

For example, CVE-2026-21643, a SQL injection vulnerability in the FortiClient Endpoint Management Server (EMS) that was found internally by Fortinet and patched in February, was eventually exploited by hackers a month later. Last month, attackers exploited another zero-day vulnerability in FortiClient EMS.

Fortinet patches critical RCEs in FortiAuthenticator and FortiSandbox

Extra corrections

In addition to the two critical vulnerabilities, Fortinet released updates for high- and medium-severity vulnerabilities in various products: an out-of-bounds write in FortiOS that can lead to RCE (CVE-2025-53844), an OS command injection vulnerability in FortiAP and FortiAP-W2 (CVE-2025-53870) that leads to privilege escalation, and a separate OS command injection vulnerability in FortiAP, FortiAP-U, and FortiAP-W2 (CVE-2025-53680) that can lead to RCE.

Exploiting these vulnerabilities requires authentication, so they are not rated as critical, but attackers often compromise corporate credentials, so they should be treated with caution.

See also: Claude Mythos finds only one vulnerability in Curl – what is it?

In conclusion, the new critical vulnerabilities in Fortinet products are a reminder once again of the importance of promptly applying security updates to infrastructure that handles critical authentication and threat detection functions. While there is no evidence of active exploitation of CVE-2026-44277 and CVE-2026-26083 so far, history has shown that cybercriminals move quickly when such vulnerabilities are disclosed, especially in products with elevated access privileges within corporate networks.

Organizations are urged not only to immediately proceed with the necessary upgrades, but also to strengthen their overall cybersecurity strategy through continuous monitoring, access control and the adoption of zero trust practices. In an environment where attacks are constantly evolving, timely vulnerability management is now a critical factor in ensuring business continuity and the protection of sensitive data.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS