Vulnerability intelligence
CVE-2026-44277
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.
CVSS Score
9.1
Critical
EPSS — Exploit Probability
0.6%
Riskier than 42% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
3 articles across 3 outlets · first covered May 13, 2026 · latest May 18, 2026
Coverage timeline
-
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flawsthehackernews.com · May 18, 2026
-
Fortinet and Ivanti patch 18 flaws, including three critical bugswww.securityweek.com · May 13, 2026
-
Fortinet patches critical RCE flaws in FortiAuthenticator, FortiSandboxsecurityaffairs.com · May 13, 2026