CVE-2026-44277Disclosure(fortinet / fortiauthenticator)

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 14 mentions and remains active

Immediate actions

  • Patch fortinet fortiauthenticator systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortiauthenticator

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 26 mentions across 6 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 22 signals
  • Disclosure: 10 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 14 mentions (2026-05-13); latest day: 1
  • 26 total mentions across 6 days

Affected systems

Vendors
Products
fortiauthenticator

Deep dive

Activity timeline26 mentions / 6d
0471114Mentions · 2026-05-12: 6Mentions · 2026-05-13: 14Mentions · 2026-05-14: 2Mentions · 2026-05-18: 1Mentions · 2026-05-19: 2Mentions · 2026-08-05: 1PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-19: 1Exploit Tool / Code · 2026-05-14: 1Active Exploitation · 2026-05-13: 2Patch / Workaround · 2026-05-12: 2Patch / Workaround · 2026-05-13: 7Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-19: 2Technical Details · 2026-05-12: 5Technical Details · 2026-05-13: 14Technical Details · 2026-05-14: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 105-1205-1305-1405-1805-1908-05
Signal classification5 categories
Disclosure
1038.5%
Patch
934.6%
General
311.5%
Active Exploitation
27.7%
PoC
27.7%
Referenced assets28 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-126
Disclosure3Patch3
2026-05-1314
Active Exploitation2Disclosure7General1Patch4
2026-05-142
General1PoC1
2026-05-181
Patch1
2026-05-192
Patch1PoC1
2026-08-051
General1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    Patch

    Urgent: Fortinet warns of 9.1 severity flaws in FortiSandbox (CVE-2026-26083) and FortiAuthenticator (CVE-2026-44277). Patch now to prevent unauthorized RCE. #Fortinet #FortiSandbox #FortiAuthenticator #CyberSecurity #InfoSec #VulnerabilityAlert #RCE https://securityonline.info/fortinet-critical-vulnerability-fortisandbox-fortiauthenticator-2026/ https://t.co/3bJN8TAfcD

    Post summary

    Fortinet warns users of two high‑severity CVEs in FortiSandbox and FortiAuthenticator, urging them to apply the available patch to prevent remote code execution.

    04071610
    12.5K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    Fortinet、FortiSandboxとFortiAuthenticatorの重大なRCE脆弱性について警告(CVE-2026-44277、CVE-2026-26083) | Codebook https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45561/ "Fortinetはこれらの脆弱性が実際の攻撃で悪用されているとは述べていないが、同社製品の脆弱性はランサムウェア攻撃やサイバースパイ活動で…"

    Post summary

    The alert announces two critical RCE CVEs (CVE‑2026‑44277 and CVE‑2026‑26083) in FortiSandbox and FortiAuthenticator, noting their severity but not confirming exploitation or providing exploit solutions.

    10041434
    3.5K followersView on X
  • Cyber Edition@CyberEdition
    Disclosure

    ⚠️ A critical FortiAuthenticator flaw (CVE-2026-44277) lets attackers execute code remotely without authentication. Internet-facing identity systems are especially at risk. Patch affected versions immediately. Read more: https://thecyberedition.com/fortiauthenticator-vulnerability-rce/ #CyberSecurity #Fortinet

    Post summary

    A critical FortiAuthenticator flaw (CVE‑2026‑44277) allows unauthenticated remote code execution; immediate patching is advised.

    0002192
    739 followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    2026年5月ぱっちちゅーずでーまとめ ◆Microsoft https://www.microsoft.com/en-us/msrc/blog/2026/05/202605-security-update CVE-2026-42898 Microsoft Dynamics 365 オンプレミスのリモートでコードが実行される脆弱性 CVE-2026-42823 Azure Logic Apps の特権昇格の脆弱性 CVE-2026-41096 Windows DNS クライアントのリモートでコードが実行される脆弱性 CVE-2026-41089 Windows Netlogon のリモートでコードが実行される脆弱性 ◆Ivanti https://www.ivanti.com/blog/may-2026-security-update critical1件 ■CVE-2026-8043(Critical) ファイル名制御不備により認証済ユーザが任意ファイル読取・HTML書込可能。情報漏えいに加え、XSS等のクライアント攻撃や踏み台化の恐れ ◆Fortinet https://fortiguard.fortinet.com/psirt critical2件 ■CVE-2026-26083(FortiSandbox / 認証不要RCE) 認可不備により未認証攻撃者がHTTPリクエスト経由で任意コード実行可能。ネットワーク越し・認証不要で悪用可能なため侵害難易度が低く、最優先でのパッチ適用が必要。 ■CVE-2026-44277(FortiAuthenticator / 認証不要RCE) APIのアクセス制御不備により未認証攻撃者が任意コマンド実行可能。IAM基盤への侵害に直結し、認証・証明書管理を含む全体統制を破壊するリスクが高い。 ◆SAP SAP Security Patch Day - January 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/january-2026.html critical4件 ■ CVE-2026-0501(SQL Injection:S/4HANA) 外部入力の検証不備によりSQLインジェクションが成立し、DBの機密情報取得・改ざん・削除が可能。業務データへの直接影響が大きい。認証済ユーザ(業務ユーザ等)でも悪用可能なケースが想定され、権限逸脱型リスクが高い。 ■ CVE-2026-0500(RCE:Wily Introscope) 細工されたリクエストにより任意コード実行が可能となる脆弱性。監視基盤の乗っ取りや横展開の踏み台となる危険がある。認証不要または低権限でも悪用できる可能性があり、外部攻撃者・内部第三者双方に対して高リスク。 ■ CVE-2026-0498(Code Injection:S/4HANA) 入力処理不備を突いたコードインジェクションにより、アプリケーション処理の改ざんや不正実行が可能。業務アプリ経由で実行されるため、正規ユーザ(認証済第三者)による悪用や、意図しない権限範囲での操作に繋がるリスクが高い。 ■ CVE-2026-0491(Code Injection:Landscape Transformation) データ移行・統合処理におけるコードインジェクションにより、システム改ざんやデータ破壊が可能。移行作業や連携処理を扱う認証済ユーザから悪用される可能性があり、内部・委託先など第三者経由での被害拡大が懸念。 ◆Adobe https://helpx.adobe.com/security.html critical4件 ■CVE-2026-34659(Adobe Connect / RCE) デシリアライズ不備により未認証攻撃者が細工データを通じて任意コード実行可能。ユーザ操作誘導で成立し、CVSS9.6の極めて高リスク脆弱性。 ■CVE-2026-34660(Adobe Connect / 権限昇格) 認可不備により権限昇格が可能。RCEと組み合わせることで完全な環境乗っ取りに発展する恐れがあり、Connect系の中でも特に影響大。 ■CVE-2026-34653(Adobe Commerce / パストラバーサル) ディレクトリ操作不備により任意ファイル書込みが可能。攻撃者によるサーバ改ざん・Webシェル設置に繋がる恐れがある重大リスク。 ■CVE-2026-34686(Adobe Commerce / XSS→RCE) 保存型XSSにより任意スクリプト実行が可能。管理画面等と組み合わせるとコード実行やセッション奪取等の高リスク攻撃に発展。

    Post summary

    The message is a vendor security update feed summarizing newly disclosed CVEs with technical details and patch advisories for Microsoft, Ivanti, Fortinet, SAP, and Adobe.

    000211.4K
    11.7K followersView on X
  • Elusive@ElusivePrivacy
    Patch

    Fortinet Critical RCE Flaws Fortinet patches two critical RCE vulnerabilities in FortiSandbox (CVE-2026-44277, CVE-2026-26083) and FortiAuthenticator (CVE-2026-21643, CVE-2026-35616). Unauthenticated attackers can run arbitrary commands or code on affected appliances. No reports of active exploitation yet. Patch immediately. Source: BleepingComputer / Fortinet PSIRT Full analysis → http://t.me/VulnerabilityNews Follow @VulnerabilityNw

    Post summary

    Fortinet released patches for four critical RCE vulnerabilities in FortiSandbox and FortiAuthenticator; no active exploitation has been reported.

    11010149
    172 followersView on X
  • David@2600Hz_
    General

    another FortiCVE {CVE-2026-44277} https://fortiguard.fortinet.com/psirt/FG-IR-26-128 https://t.co/r0IMS816xA

    Post summary

    The text merely references a FortiCVE ID and provides two URLs, without detailed technical info, PoC, exploit, or patch details.

    0002080
    3.1K followersView on X
  • Login Sécurité@LoginSecurite
    Disclosure

    🚨 Alertes sécurité : CVE-2026-26083 et CVE-2026-44277 sur FortiSandbox et FortiAuthenticator Des failles FortiSandbox et FortiAuthenticator permettent l'exécution de commandes à distance sans authentification. Plus d'informations : https://login-securite.com/alertes/fr-vulnerabilite-critique-dans-fortisandbox-et-fortiauthenticator

    Post summary

    An alert announces newly disclosed CVE‑2026‑26083 and CVE‑2026‑44277 affecting FortiSandbox and FortiAuthenticator, describing remote command execution without authentication; further details are available via the provided link.

    0002091
    553 followersView on X
  • Machina Record@MachinaRecord
    Disclosure

    🚨Fortinet、FortiSandboxとFortiAuthenticatorの重大なRCE脆弱性について警告(CVE-2026-44277、CVE-2026-26083) 🩹マイクロソフト、5月の月例パッチで脆弱性120件を修正 ゼロデイは含まれず(CVE-2026-35421、CVE-2026-40365他) 〜サイバーアラート5月13日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45561/

    Post summary

    The post warns of critical remote code execution flaws in Fortinet’s FortiSandbox and FortiAuthenticator (CVE‑2026‑44277, CVE‑2026‑26083) and notes that Microsoft’s May patch round addressed 120 vulnerabilities (including CVE‑2026‑35421, CVE‑2026‑40365) with no zero‑day fixes.

    00020224
    1.3K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - FortiAuthenticator Improper Access Control on API Endpoints (CVE-2026-44277) An Improper Access Control vulnerability in FortiAuthenticator API endpoints allows an unauthenticated attacker to execute unauthorized code or commands via specially crafted requests. This can lead to full system compromise, data theft, or unauthorized administrative actions. 👉Affected: FortiAuthenticator 8.0.0 - 8.0.2, 6.6.0 - 6.6.8, 6.5.0 - 6.5.6

    Post summary

    The tweet announces a critical FortiAuthenticator CVE-2026-44277 that permits unauthenticated attackers to run code via the API, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0002096
    187 followersView on X
  • ALL IT Services@ALLITAustralia
    PoC

    FortiAuthenticator critical bug (CVE-2026-44277) is patched but a public PoC just dropped — update today. #CyberSecurity #AusIT https://allitservices.com.au/fortiauthenticator-critical-flaw-cve-2026-44277-patch-your-mfa-today/

    Post summary

    A public PoC for FortiAuthenticator CVE-2026-44277 was released; users are urged to apply the existing patch.

    0001060
    16 followersView on X
  • TodayInCyber@TodayInCyberIO
    Patch

    2/5 Ivanti Xtraction (CVE-2026-8043): a critical flaw enabling information disclosure and client-side attacks. Patch released. Fortinet FortiAuthenticator and FortiSandbox (CVE-2026-44277, CVE-2026-26083): critical vulnerabilities enabling remote code execution.

    Post summary

    The text reports critical vulnerabilities in Ivanti Xtraction, Fortinet FortiAuthenticator, and FortiSandbox, noting a patch release for the former and highlighting the severity of the flaws.

    100003
    8 followersView on X
  • Jaden Johnson@JadenJohnsNews
    Disclosure

    🚨 CRITICAL Fortinet Alert Two critical vulnerabilities affecting Fortinet products could allow unauthenticated attackers to execute arbitrary code/commands via malicious requests: 🔴 CVE-2026-44277 — FortiAuthenticator 🔴 CVE-2026-26083 — FortiSandbox / FortiSandbox Cloud/PaaS https://t.co/3fb2dehrwE

    Post summary

    Fortinet has disclosed two critical vulnerabilities (CVE-2026-44277 and CVE-2026-26083) that could allow unauthenticated attackers to execute arbitrary code on affected products.

    00010764
    221 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-44277: FortiAuthenticator Improper Access Control - What It Means for Your Business and How to Respond https://hubs.li/Q04s1JDK0

    Post summary

    The article headline references CVE‑2026‑44277 but contains no detailed information about the vulnerability, exploitation, or remediation.

    0000035
    32 followersView on X
  • isogashii@cyber_risk_sec
    Patch

    4. Fortinet FortiAuthenticator CVE-2026-44277(CVSS 9.1) 不正アクセス制御の脆弱性。FortiSandbox / FortiSandbox Cloud / PaaSも影響。未認証のリモート攻撃者がコード実行可能。パッチ公開済み・即時適用推奨。原典: https://www.fortiguard.com/psirt

    Post summary

    The post announces the Fortinet FortiAuthenticator CVE-2026-44277 vulnerability, highlights its high severity and remote code execution potential, and confirms a patch is available and should be applied immediately.

    0000072
    121 followersView on X
  • dbugs@ptdbugs
    PoC

    CVE: CVE-2026-44277 PT ID: PT-2026-40265 Vendor: Fortinet Product: FortiAuthenticator CVSS: 9.1 Credits: n/a Description: A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-44277 • https://fortiguard.fortinet.com/psirt/FG-IR-26-128 PoC/Exploit: https://github.com/0xBlackash/CVE-2026-44277 #dbugs_vuln

    Post summary

    CVE-2026-44277 is an improper access control flaw in FortiAuthenticator (CVSS 9.1) that allows unauthorized command execution, with a publicly available PoC/exploit on GitHub.

    00000153
    1.2K followersView on X
  • ohhara_P🧐Slow life in the isekai@ohhara_shiojiri
    Disclosure

    Fortinet、FortiSandboxとFortiAuthenticatorの重大なRCE脆弱性について警告(CVE-2026-44277、CVE-2026-26083) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45561/

    Post summary

    The post warns of major RCE vulnerabilities (CVE-2026-44277 & CVE-2026-26083) in Fortinet products but offers no PoC, exploit details, or patch information.

    0000078
    2.0K followersView on X
  • Cyberdark Imapct@kenebeii
    General

    🔐 セキュリティトレンド (16:23 JST) ① Mini Shai-Hulud Is Back:新たなサプライチェーン攻撃がTanStackやMistral AIのパッケージを襲撃 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45547/ ② SAP、Commerce CloudとS/4HANAのCriticalな脆弱性に対処:CVE-2026-34263 - Codebook https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45556/ ③ マイクロソフトがイスラエル子会社のトップを解任、パレスチナ人の監視問題めぐり - Codebook https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45552/ ④ 2026年5月マイクロソフトセキュリティ更新プログラムに関する注意喚起 - JPCERT https://www.jpcert.or.jp/at/2026/at260012.html ⑤ FortiSandboxとFortiAuthenticatorの重大なRCE脆弱性について警告(CVE-2026-44277 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45561/ #セキュリティ #CyberSecurity

    Post summary

    The text lists two CVEs (CVE‑2026‑34263 and CVE‑2026‑44277) and gives minimal technical detail (notably an RCE for the latter) but does not provide PoC, exploits, patches, or active exploitation evidence.

    000007
    182 followersView on X
  • ByteCheck@ByteCheck101
    Patch

    @Fortinet warns of 2 critical RCE flaws CVE-2026-44277 (FortiAuthenticator): Unauthenticated RCE via improper access control. Fixed in 6.5.7 / 6.6.9 / 8.0.3 (Cloud not affected). CVE-2026-26083 (FortiSandbox): Missing authorization leading to RCE on WEB UI. Patch ASAP — Fortinet bugs get weaponized fast. #CyberSecurity #Fortinet

    Post summary

    Fortinet alerts about two critical RCE CVEs, specifies affected products and fixed versions, and urges immediate patching.

    0000048
    10 followersView on X
  • ThreatAft@ThreatAft
    Patch

    🚨 Fortinet emergency patch: Two critical RCE flaws (CVSS 9.1 each) in FortiSandbox and FortiAuthenticator. CVE-2026-44277 — unauthenticated RCE in IAM solution CVE-2026-26083 — unauthenticated RCE via WEB UI 🔗 https://threataft.com/articles/fortinet-critical-rce-fortisandbox-fortiauthenticator #CyberSecurity #ThreatIntel #Fortinet

    Post summary

    Fortinet has issued an emergency patch for two critical unauthenticated RCE vulnerabilities (CVSS 9.1 each). No PoC or active exploitation is mentioned.

    0000093
    24 followersView on X
  • Techgines@nxtgen579255
    Patch

    🚨 BREAKING — Fortinet just patched two CRITICAL unauthenticated RCE flaws: → CVE-2026-44277 (FortiAuthenticator) — CWE-284 Improper Access Control. Crafted HTTP request = unauthorized code execution on your IAM layer. No auth needed. https://www.techgines.com/post/fortinet-fortiauthenticator-rce-cve-2026-44277-fortisandbox https://t.co/2U6a6QHVSO

    Post summary

    Fortinet has released a patch for CVE-2026-44277, a critical unauthenticated RCE flaw in FortiAuthenticator that allows code execution via crafted HTTP requests without authentication, with no evidence of current exploitation or a published PoC.

    0000043
    5 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortiauthenticator---

Explore more