惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
人人都是产品经理
人人都是产品经理
小众软件
小众软件
博客园 - Franky
WordPress大学
WordPress大学
Jina AI
Jina AI
Google DeepMind News
Google DeepMind News
I
InfoQ
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
F
Fortinet All Blogs
博客园 - 【当耐特】
IT之家
IT之家
G
Google Developers Blog
J
Java Code Geeks
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
云风的 BLOG
云风的 BLOG
Recent Announcements
Recent Announcements
有赞技术团队
有赞技术团队
V
Visual Studio Blog
U
Unit 42
阮一峰的网络日志
阮一峰的网络日志
月光博客
月光博客
GbyAI
GbyAI
雷峰网
雷峰网

CSO Online

New malware turns Linux systems into P2P attack networks Poisoned truth: The quiet security threat inside enterprise AI Train like you fight: Why cyber operations teams need no-notice drills Die besten DAST- & SAST-Tools CISA mulls new three-day remediation deadline for critical flaws CISA pushes critical infrastructure operators to prepare to work in isolation CISOs step up to the security workforce challenge 10 Anzeichen für einen schlechten CSO Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models Security agencies draw red lines around agentic AI deployments The fake IT worker problem CISOs can’t ignore How CISOs should utilize data security posture management to inform risk Was ist ein Botnet? Human-centric failures: Why BEC continues to work despite MFA Just 34% of cyber pros plan to stick with their current employer Managing OT risk at scale: Why OT cyber decisions are leadership decisions 4 ways to prepare your SOC for agentic AI ‘Trivial’ exploit can give attackers root access to Linux kernel Bank regulator sounds warning over cybersecurity threat posed by AI models Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators Max-severity RCE flaw found in Google Gemini CLI Stopping the quiet drift toward excessive agency with re-permissioning ODNI to CISOs on threat assessments: You’re on your own 10 wichtige Security-Eigenschaften: So setzen Sie die Kraft Ihres IT-Sicherheitstechnik-Teams frei Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years AWS leans on prior ingenuity to face future AI and quantum threats What it takes to win that CSO role Third Party Risk Management: So vermeiden Sie Compliance-Unheil Critical Cursor bug could turn routine Git into RCE Securing RAG pipelines in enterprise SaaS
Fortinet fixes two critical RCE flaws in FortiAuthenticat...
2026-05-14 · via CSO Online

Fortinet released a batch of patches across its products on Patch Tuesday, including two critical vulnerabilities that can lead to remote code execution. Fortinet flaws, both zero-day and n-day, have been exploited in the wild many times in the past, so companies should deploy patches as soon as possible.

“Fortinet vulnerabilities are often attractive to threat actors because these products sit in high-trust security functions that threat actors often target,” Piyush Sharma, CEO and co-founder of SecOps company Tuskira, told CSO via email. “When a vulnerability affects a tool that already has privileged visibility or sits close to critical systems, exploitation can give attackers a much larger head start than a flaw in an ordinary application.”

The flaw in FortiAuthenticator, tracked as CVE-2026-44277, has a 9.1 CVSS severity score and is described as an improper access control issue. Successful exploitation allows unauthenticated attackers to execute unauthorized code and commands by sending specifically crafted requests.

An identity and access management (IAM) solution, FortiAuthenticator serves as the central hub for RADIUS, LDAP, and SAML authentication. It integrates with Active Directory and supports single sign-on and multi-factor authentication. To patch this new vulnerability, companies are advised to upgrade to FortiAuthenticator 6.5.7, 6.6.9, or 8.0.3 depending on the release they’re using.

The flaw in FortiSandbox is a missing authorization issue that similarly allows unauthenticated attackers to execute arbitrary code and commands via HTTP requests. Tracked as CVE-2026-26083, the vulnerability also has a severity score of 9.1.

FortiSandbox is a threat detection solution designed to identify zero-day threats by using machine learning to perform static and dynamic analysis on suspicious files inside an isolated environment. It integrates with other Fortinet security products such as FortiGate and FortiMail and comes in different variants, including hardware and virtual appliances.

The vulnerability impacts all supported versions of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. Users are advised to upgrade to version 4.4.9 or 5.0.2, depending on release.

Both CVE-2026-26083 and CVE-2026-44277 were discovered internally by Fortinet, so there is no evidence of in-the-wild exploitation yet. However, exploits for other Fortinet RCE vulnerabilities were adopted by attackers in the past.

For example, CVE-2026-21643, an SQL injection vulnerability in FortiClient Endpoint Management Server (EMS) that was found internally by Fortinet and was patched in February, ended up exploited in the wild a month later. This was followed up last month by exploitation of another FortiClient EMS flaw, this time a zero-day.

In addition to the two critical flaws, Fortinet released patches for high- and medium-severity flaws in several products: an out-of-bounds write vulnerability in FortiOS that can lead to RCE (CVE-2025-53844), an OS command injection vulnerability in FortiAP and FortiAP-W2 (CVE-2025-53870) that leads to privilege escalation, and a separate OS command injection flaw in FortiAP, FortiAP-U, and FortiAP-W2 (CVE-2025-53680) that can lead to RCE.

Exploitation of these flaws requires authentication, which is why they’re not rated critical, but attackers compromising enterprise credentials is not uncommon so they should still be treated with urgency.

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.