Summary
Fortinet has issued urgent patches for critical vulnerabilities in two of its security products: FortiSandbox and FortiAuthenticator. Both flaws allow unauthenticated attackers to execute unauthorized code or commands remotely, making them high-priority targets for exploitation.
The FortiAuthenticator vulnerability (CVE-2026-44277) is an improper access control issue, while the FortiSandbox flaw (CVE-2026-26083) stems from missing authorization checks. In both cases, no authentication is required to exploit the vulnerabilities — a worst-case scenario for network security appliances that are supposed to be trust boundaries.
Fortinet published advisories and patches on May 13, 2026, and is urging all customers to update immediately. Given Fortinet’s track record of being targeted by state-sponsored groups (including recent campaigns against FortiGate devices), rapid patching is essential.
Sources
Commentary
Security appliances with unauthenticated RCE vulnerabilities are the definition of irony — the devices meant to protect your network become the entry point. Fortinet products have been a favorite target of APT groups for years, and these flaws will almost certainly see exploitation attempts within days of disclosure.
If you’re running FortiSandbox or FortiAuthenticator, treat this as a drop-everything-and-patch situation. The combination of no-auth-required access and remote code execution on security infrastructure is about as bad as it gets.
