Fortinet has issued a high-priority warning regarding two separate critical vulnerabilities affecting core security components: FortiSandbox and FortiAuthenticator. Both flaws carry a CVSS score of 9.1, signaling a “Critical” severity that could allow unauthenticated attackers to execute unauthorized code or commands.
The first vulnerability, tracked as CVE-2026-26083, targets the Web UI of FortiSandbox, including its Cloud and PaaS (Platform as a Service) variations. This is a Missing Authorization [CWE-862] flaw.
A lack of proper authorization checks in the Web UI allows an unauthenticated attacker to bypass security hurdles. By sending specifically crafted HTTP requests, an attacker can execute unauthorized code or commands on the system.
Because a sandbox is often used to analyze the most dangerous malware in an isolated environment, an escape or compromise of the sandbox itself could have devastating consequences for the broader network.
| Product Version | Affected Range | Solution |
| FortiSandbox 5.0 |
5.0.0 through 5.0.1 |
Upgrade to 5.0.2 or above |
| FortiSandbox 4.4 |
4.4.0 through 4.4.8 |
Upgrade to 4.4.9 or above |
| FortiSandbox Cloud 5.0 |
5.0.2 through 5.0.5 |
Upgrade to 5.0.6 or above |
| FortiSandbox Cloud 23/24 |
All versions |
Migrate to a fixed release |
| FortiSandbox PaaS |
Various (see advisory) |
Upgrade/Migrate as specified |
The second critical issue, tracked as CVE-2026-44277, hits FortiAuthenticator, the cornerstone of many organizations’ identity and access management (IAM) strategies. This is an Improper Access Control [CWE-284] vulnerability.
Similar to the sandbox flaw, this vulnerability allows unauthenticated attackers to send crafted requests to the system.
Attackers can execute unauthorized code or commands, potentially compromising the very system responsible for verifying user identities and managing access keys.
FortiAuthenticator Cloud is confirmed to be not impacted by this specific issue.
| Product Version | Affected Range | Solution |
| FortiAuthenticator 8.0 |
8.0.0, 8.0.2 |
Upgrade to 8.0.3 or above |
| FortiAuthenticator 6.6 |
6.6.0 through 6.6.8 |
Upgrade to 6.6.9 or above |
| FortiAuthenticator 6.5 |
6.5.0 through 6.5.6 |
Upgrade to 6.5.7 or above |
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.