Fortinet Critical Unauthenticated RCE — FortiAuthenticator CVE-2026-44277 & FortiSandbox CVE-2026-26083 — Threadlinqs Intelligence
As of 2026-05-30, Fortinet Critical Unauthenticated RCE — FortiAuthenticator CVE-2026-44277 & FortiSandbox CVE-2026-26083 is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-0503 · Severity: CRITICAL · CVSS: 9.8 · Status: MONITORING · Category: VULNERABILITY
Fortinet PSIRT disclosed two CRITICAL unauthenticated remote code execution vulnerabilities on 2026-05-12 affecting FortiAuthenticator (CVE-2026-44277, FG-IR-26-128, CWE-284 Improper Access Control on
On 2026-05-12 Fortinet's Product Security Incident Response Team (PSIRT) published two synchronized advisories disclosing CRITICAL unauthenticated remote code execution vulnerabilities in two of its core identity and threat-analysis products: FortiAuthenticator (FG-IR-26-128 / CVE-2026-44277) and FortiSandbox plus its Cloud and PaaS variants (FG-IR-26-136 / CVE-2026-26083). Both vulnerabilities share the same CVSSv3.1 vector — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — yielding an NVD base score of 9.8 (Fortinet PSIRT lists 9.1 internally). The combination of network-reachable attack surface, no authentication, no user interaction, and high impact across confidentiality, integrity, and availability marks both as drop-everything patch priorities for any organization running affected versions.
CVE-2026-44277 is an Improper Access Control weakness (CWE-284) in FortiAuthenticator's API endpoint authorization logic. FortiAuthenticator is Fortinet's identity-management appliance: it handles RADIUS, LDAP proxy, certificate issuance, two-factor authentication tokens, FSSO collector, and SAML/OIDC federation for the Fortinet Security Fabric. Affected versions include 8.0.0 and 8.0.2, 6.6.0 through 6.6.8, and 6.5.0 through 6.5.6, fixed in 8.0.3, 6.6.9, and 6.5.7 respectively. FortiAuthenticator Cloud is explicitly not impacted. Because the product brokers authentication for downstream Fortinet appliances, a compromised FortiAuthenticator can mint or extract credentials, issue rogue certificates, manipulate FSSO mappings, and pivot into protected networks under valid-account cover — a classic identity-tier blast-radius scenario reminiscent of the 2024 FortiManager FortiJump (CVE-2024-47575) chain, except striking the directory and 2FA layer directly.
CVE-2026-26083 is a Missing Authorization weakness (CWE-862) in the FortiSandbox WEB UI. FortiSandbox is Fortinet's network sandbox / detonation chamber for suspicious files and URLs; it is deployed inline behind FortiGate, FortiMail, and FortiWeb to perform behavioural malware analysis. Affected on-prem versions are 5.0.0 through 5.0.1 and 4.4.0 through 4.4.8 (fixed in 5.0.2 and 4.4.9). FortiSandbox Cloud 24, Cloud 23, Cloud 5.0.2-5.0.5 are affected (fixed in Cloud 5.0.6). FortiSandbox PaaS is affected across releases 21.3, 21.4, 22.1, 22.2, 23.1, 23.3, 23.4, 5.0.0-5.0.1, and 4.4.5-4.4.8 (fixed in PaaS 5.0.2 and 4.4.9). Exploitation is via HTTP requests against the WEB UI: an unauthenticated attacker can invoke privileged actions that are missing authorization checks, leading to code execution in the appliance context. Post-exploit access to a FortiSandbox is highly valuable to an adversary because (a) it sees and stores adversary samples submitted across the Security Fabric, (b) it can be coerced into returning benign verdicts for attacker-controlled samples, blinding upstream FortiGate/FortiMail decisions, and (c) the appliance is trusted by adjacent devices for sample submission and verdict callbacks.
No public PoC, exploit chain, or in-the-wild exploitation has been reported as of the 2026-05-12 publication. Both vulnerabilities were discovered internally — CVE-2026-44277 by Fortinet's internal audit team, CVE-2026-26083 credited to Adham El karn of Fortinet Product Security. However, Fortinet edge and security-fabric appliances have a documented and aggressive weaponization curve: 26 Fortinet CVEs are listed in the CISA Known Exploited Vulnerabilities catalog, and recent classes including FortiOS authentication bypass (CVE-2022-40684), FortiGate SSL-VPN heap overflow (CVE-2022-42475), FortiOS path traversal (CVE-2022-41328), and the FortiJump FortiManager chain (CVE-2024-47575) all moved from advisory to active exploitation within days to weeks. The unauthenticated network-reachable nature of both 2026-05-12 advisories, combined with the high-value role of identity and malware-analysis appliances inside the kill chain, makes both strong candidates for short-fuse weaponization by both nat
Weaknesses (CWE)
CWE-284, CWE-862
Target sectors: government, defense, financial, healthcare, energy, telecommunications, manufacturing, managed-security-service-providers, education, technology
Target regions: Global, North America, Europe, Asia-Pacific, Middle East
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-44277, CVE-2026-26083, T1595, T1595.002, T1592, T1587.004, T1588.005, T1190, T1133, T1059, T1059.004, T1505.003