Fortinet has released a series of security updates for its products, fixing, among other things, two critical vulnerabilities that could lead to remote code execution . Fortinet vulnerabilities, whether zero-day or n-day, have been exploited many times in the past, so companies should apply the updates as soon as possible.

“ Fortinet vulnerabilities are often attractive to malicious users because these products are located in high-trust functions that attackers often target ,” Piyush Sharma , CEO and co-founder of SecOps firm Tuskira, told CSO . “ When a vulnerability affects a tool that already has privileged visibility or is close to critical systems, exploitation can give attackers a much greater head start than a vulnerability in a common application .”
See also: MDASH: Microsoft's new AI system finds 16 vulnerabilities in Windows
Fortinet: FortiAuthenticator Vulnerability
The vulnerability in FortiAuthenticator, codenamed CVE-2026-44277, has a CVSS score of 9.1 and is described as an improper access control. Successful exploitation allows unauthenticated attackers to execute unauthorized code and commands by sending specially crafted requests.
FortiAuthenticator, an identity and access management (IAM) solution, acts as a central hub for RADIUS, LDAP, and SAML authentication . It integrates with Active Directory and supports single sign-on and multi-factor authentication .
To fix this new vulnerability, companies are urged to upgrade to FortiAuthenticator 6.5.7, 6.6.9 or 8.0.3 depending on the version they are using.

Fortinet: FortiSandbox vulnerability
The FortiSandbox vulnerability is an authorization that also allows unauthenticated attackers to execute arbitrary code and commands via HTTP requests. Codenamed CVE-2026-26083, the vulnerability also has a CVSS score of 9.1.
See also: New Exim BDAT vulnerability exposes GnuTLS constructs
FortiSandbox is a threat detectiondesigned to identify zero-day threats using machine learning to perform static and dynamic analysis on suspicious files within an isolated environment. It integrates with other Fortinet security products such as FortiGate and FortiMail and is available in various versions, including hardware and virtual appliances.
The vulnerability affects all supported versions of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. Users are advised to upgrade to version 4.4.9 or 5.0.2, depending on the version.
Fortinet vulnerability exploitation
CVE-2026-26083 and CVE-2026-44277 were discovered internally by Fortinet and there is currently no evidence of exploitation. However, exploits for other Fortinet RCE vulnerabilities have been used by attackers in the past.
For example, CVE-2026-21643, a SQL injection vulnerability in the FortiClient Endpoint Management Server (EMS) that was found internally by Fortinet and patched in February, was eventually exploited by hackers a month later. Last month, attackers exploited another zero-day vulnerability in FortiClient EMS.

Extra corrections
In addition to the two critical vulnerabilities, Fortinet released updates for high- and medium-severity vulnerabilities in various products: an out-of-bounds write in FortiOS that can lead to RCE (CVE-2025-53844), an OS command injection vulnerability in FortiAP and FortiAP-W2 (CVE-2025-53870) that leads to privilege escalation, and a separate OS command injection vulnerability in FortiAP, FortiAP-U, and FortiAP-W2 (CVE-2025-53680) that can lead to RCE.
Exploiting these vulnerabilities requires authentication, so they are not rated as critical, but attackers often compromise corporate credentials, so they should be treated with caution.
See also: Claude Mythos finds only one vulnerability in Curl – what is it?
In conclusion, the new critical vulnerabilities in Fortinet products are a reminder once again of the importance of promptly applying security updates to infrastructure that handles critical authentication and threat detection functions. While there is no evidence of active exploitation of CVE-2026-44277 and CVE-2026-26083 so far, history has shown that cybercriminals move quickly when such vulnerabilities are disclosed, especially in products with elevated access privileges within corporate networks.
Organizations are urged not only to immediately proceed with the necessary upgrades, but also to strengthen their overall cybersecurity strategy through continuous monitoring, access control and the adoption of zero trust practices. In an environment where attacks are constantly evolving, timely vulnerability management is now a critical factor in ensuring business continuity and the protection of sensitive data.
