Fortinet Patches Auth-Bypass RCE Flaws
Fortinet FortiAuthenticator and FortiSandbox contain unauthenticated access-control flaws that could let attackers execute remote code, with no known active exploitation yet.
CISecurity/MS-ISAC issued an advisory detailing two vulnerabilities in Fortinet products: an improper access control flaw in FortiAuthenticator (CVE-2026-44277) and a missing authorization flaw in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS web UI (CVE-2026-26083). Both flaws could allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests, potentially leading to full system compromise depending on account privileges.
The advisory maps both issues to MITRE ATT&CK's Exploitation of Public-Facing Application technique under the Initial Access tactic. There are currently no reports of in-the-wild exploitation. Affected versions include FortiAuthenticator prior to 8.0.3, FortiSandbox prior to 5.0.2, FortiSandbox Cloud prior to 5.0.6, and FortiSandbox PaaS prior to 5.0.2. Organizations are urged to apply vendor hotfixes and updates promptly, enforce least privilege, conduct vulnerability scanning, and segment network architecture to limit exposure of these internet-facing identity and sandboxing appliances.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-fortinet-products-could-allow-for-remote-code-execution_2026-049
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free