LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-44277

fortinet · fortiauthenticator

Published
CVSS9.8
Severitycritical
WeaknessCWE-284
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-44277

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-44277.