{"id":246206,"date":"2026-05-13T02:50:00","date_gmt":"2026-05-13T06:50:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/05\/13\/critical-fortinet-vulnerabilities-fixed-in-fortisandbox-and-fortiauthenticator\/"},"modified":"2026-05-14T19:15:10","modified_gmt":"2026-05-14T23:15:10","slug":"critical-fortinet-vulnerabilities-fixed-in-fortisandbox-and-fortiauthenticator","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/05\/13\/critical-fortinet-vulnerabilities-fixed-in-fortisandbox-and-fortiauthenticator\/","title":{"rendered":"Critical fortinet vulnerabilities fixed in FortiSandbox and FortiAuthenticator"},"content":{"rendered":"<p><a href=\"https:\/\/securityaffairs.com\/192047\/security\/critical-fortinet-vulnerabilities-fixed-in-fortisandbox-and-fortiauthenticator.html\">Critical fortinet vulnerabilities fixed in FortiSandbox and FortiAuthenticator<\/a><\/p>\n<p><a href=\"https:\/\/securityaffairs.com\/192047\/security\/critical-fortinet-vulnerabilities-fixed-in-fortisandbox-and-fortiauthenticator.html\">https:\/\/securityaffairs.com\/192047\/security\/critical-fortinet-vulnerabilities-fixed-in-fortisandbox-and-fortiauthenticator.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-13 02:50:00<\/a><\/p>\n<p>Source Domain: <a href=\"securityaffairs.com\">securityaffairs.com<\/a><\/p>\n<p><h2>Critical Fortinet vulnerabilities fixed in FortiSandbox and FortiAuthenticator<\/h2>\n<\/p>\n<p>\t\t\t\t\t\t\t<span> Pierluigi Paganini<\/span><br \/>\n\t\t\t\t\t\t\t<span><img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> May 13, 2026<\/span><\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2019\/11\/fortinet-logo.jpg?fit=730%2C480&#038;ssl=1\" alt=\"\"\/><\/p>\n<h2 class=\"wp-block-heading\">Fortinet patched critical flaws in FortiSandbox and FortiAuthenticator that could let attackers remotely execute code on unpatched systems.<\/h2>\n<p>Fortinet addressed two critical vulnerabilities affecting FortiSandbox and FortiAuthenticator. The flaws could allow attackers to execute arbitrary commands or code on unpatched systems. <\/p>\n<p>The first vulnerability, tracked as CVE-2026-44277, is an improper access control issue in FortiAuthenticator.<\/p>\n<p>\u201cAn Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.\u201d reads the advisory.<\/p>\n<p>Below are the impacted versions:<\/p>\n<table class=\"has-fixed-layout\">\n<tr>\n<th>Version<\/th>\n<th>Affected<\/th>\n<th>Solution<\/th>\n<\/tr>\n<tr>\n<td>FortiAuthenticator 8.0<\/td>\n<td>8.0.2<\/td>\n<td>Upgrade to 8.0.3 or above<\/td>\n<\/tr>\n<tr>\n<td>FortiAuthenticator 8.0<\/td>\n<td>8.0.0<\/td>\n<td>Upgrade to 8.0.3 or above<\/td>\n<\/tr>\n<tr>\n<td>FortiAuthenticator 6.6<\/td>\n<td>6.6.0 through 6.6.8<\/td>\n<td>Upgrade to 6.6.9 or above<\/td>\n<\/tr>\n<tr>\n<td>FortiAuthenticator 6.5<\/td>\n<td>6.5.0 through 6.5.6<\/td>\n<td>Upgrade to 6.5.7 or above<\/td>\n<\/tr>\n<\/table>\n<p>The vulnerability doesn\u2019t affect FortiAuthenticator Cloud.<\/p>\n<p>Fortinet experts discovered the flaw as part of an internal audit.<\/p>\n<p>The second flaw addressed by the cybersecurity vendor is a missing authorization issue, tracked as CVE-2026-26083, in FortiSandbox. An attacker can trigger the flaw to achieve remote code execution on vulnerable systems.<\/p>\n<p>\u201cA missing authorization vulnerability [CWE-862] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests.\u201d reads the advisory.<\/p>\n<p>Neither flaw has been exploited in in-the-wild attacks.<\/p>\n<p>Adham El Karn from the Fortinet Product Security team discovered and reported the issue internally.<\/p>\n<p><strong>Follow me on&#8230;<\/strong><\/p>\n<p><a href=\"https:\/\/securityaffairs.com\/192047\/security\/critical-fortinet-vulnerabilities-fixed-in-fortisandbox-and-fortiauthenticator.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical fortinet vulnerabilities fixed in FortiSandbox and FortiAuthenticator https:\/\/securityaffairs.com\/192047\/security\/critical-fortinet-vulnerabilities-fixed-in-fortisandbox-and-fortiauthenticator.html Publish Date: 2026-05-13 02:50:00 Source Domain:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":246207,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/securityaffairs.com\/wp-content\/uploads\/2019\/11\/fortinet-logo.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,27],"class_list":["post-246206","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/246206"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=246206"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/246206\/revisions"}],"predecessor-version":[{"id":246208,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/246206\/revisions\/246208"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/246207"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=246206"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=246206"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=246206"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}