---
schema: 1
kind: vulnerability
title: CVE-2026-44277 / CVE-2026-26083 — Fortinet FortiAuthenticator and FortiSandbox unauthenticated RCE
headline: CVE-2026-44277 / CVE-2026-26083 — Fortinet FortiAuthenticator and FortiSandbox unauthenticated RCE
summary: "Fortinet ships two pre-auth RCEs. CVE-2026-44277 (FortiAuthenticator, CVSS 9.1, CWE-284) and CVE-2026-26083 (FortiSandbox, CVSS 9.1, CWE-862) — unauthenticated network attacker can reach the management surface; FortiAuthenticator commonly anchors Swiss federal/cantonal SAML federations and RADIUS, FortiSandbox underpins SOC malware-analysis pipelines. No ITW exploitation observed at disclosure; fixed in 6.5.7 / 6.6.9 / 8.0.3 (FortiAuthenticator) and 4.4.9 / 5.0.2 / Cloud 5.0.6 (FortiSandbox) (NCSC-CH Security Hub #12569, 2026-05-13; BleepingComputer, 2026-05-13)."
discovered_at: "2026-05-13T05:00:02Z"
event_date: 2026-05-13
run_id: 2026-05-13-c148b9a5
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - pre-auth
  - rce
  - identity
  - patch-available
regions:
  - global
sectors: []
entities: []
cves:
  - id: CVE-2026-44277
    cvss: "9.1"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-26083
    cvss: "9.1"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://fortiguard.fortinet.com/psirt/FG-IR-26-128"
    publisher: "Fortinet PSIRT FG-IR-26-128, 2026-05-12"
    role: primary
  - url: "https://fortiguard.fortinet.com/psirt/FG-IR-26-136"
    publisher: "Fortinet PSIRT FG-IR-26-136, 2026-05-12"
    role: corroborating
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12569"
    publisher: "NCSC-CH Security Hub #12569, 2026-05-13"
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-rce-flaws-in-fortisandbox-and-fortiauthenticator/"
    publisher: "BleepingComputer, 2026-05-13"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-13.md
---

Fortinet published two PSIRT advisories on 2026-05-12, picked up by NCSC-CH within hours. CVE-2026-44277 (CWE-284 Improper Access Control) is an unauthenticated network attacker reaching the FortiAuthenticator management-interface API and executing arbitrary commands via crafted requests; vendor PSIRT lists CVSS 9.1 (NCSC-CH and some early reports surfaced 9.8 — § 7 documents the convergence). Affected: 6.5.0–6.5.6, 6.6.0–6.6.8 and 8.0.0–8.0.2. Fixed in 6.5.7 / 6.6.9 / 8.0.3. FortiAuthenticator Cloud (IDaaS) is **not** affected ([Fortinet PSIRT FG-IR-26-128, 2026-05-12](https://fortiguard.fortinet.com/psirt/FG-IR-26-128); [NCSC-CH Security Hub #12569, 2026-05-13](https://security-hub.ncsc.admin.ch/#/posts/12569)). CVE-2026-26083 (CWE-862 Missing Authorization) is an unauthenticated attacker reaching the FortiSandbox Web UI and executing code at CVSS 9.1 per the Fortinet PSIRT advisory ([Fortinet PSIRT FG-IR-26-136, 2026-05-12](https://fortiguard.fortinet.com/psirt/FG-IR-26-136); [BleepingComputer, 2026-05-13](https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-rce-flaws-in-fortisandbox-and-fortiauthenticator/)). Affected FortiSandbox: 4.4.0–4.4.8 (fixed 4.4.9), 5.0.0–5.0.1 (fixed 5.0.2), plus multiple PaaS / Cloud variants; on-prem Cloud 23 and 24 require migration rather than an in-place patch. Both discoveries are attributed to internal Fortinet audit; exploitation status is unknown at disclosure. The defender-relevant attack surface is the network-reachable management plane on each appliance class. Detection concepts mapped to `T1190 Exploit Public-Facing Application`: alert on FortiAuthenticator / FortiSandbox management-port reach from outside the SOC management VLAN; treat any anomalous outbound HTTP from these appliances (Sysmon-equivalent on FortiOS via `diagnose debug application httpsd` for FortiAuthenticator) as potential post-exploit egress. Hardening: enforce the perimeter / internal firewall rule that FortiAuthenticator GUI / API and FortiSandbox Web UI are reachable only from named admin / SOC source IPs — Fortinet's PSIRT pages explicitly call this out as the residual hardening even after patching.
