Critical severity9.8NVD Advisory· Published May 12, 2026· Updated May 15, 2026
CVE-2026-44277
CVE-2026-44277
Description
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Affected products
1- Range: 6.5.0-6.5.6, 6.6.0-6.6.8, 8.0.0, 8.0.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- fortiguard.fortinet.com/psirt/FG-IR-26-128nvdVendor Advisory
News mentions
3- Fortinet, Ivanti Patch Critical VulnerabilitiesSecurityWeek · May 13, 2026
- Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticatorBleepingComputer · May 12, 2026
- Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-daysBleepingComputer · May 12, 2026