High severity7.5NVD Advisory· Published Mar 24, 2025· Updated Jun 17, 2026
CVE-2021-26091
CVE-2021-26091
Description
A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to infer parts of users authentication tokens and reset their credentials.
Affected products
3Patches
Vulnerability mechanics
References
1- fortiguard.com/advisory/FG-IR-21-031nvdVendor Advisory
News mentions
0No linked articles in our index yet.