Header image overlay

CVEs for Fortigate and FortiAuthenticator

Our experts keep you up-to-date on critical cyber threats (CVEs)

Two security issues have been discovered in the FortiGate and FortiAuthenticator Fortinet products; these are urgent but, fortunately, can be easily resolved with an upgrade.

CVEs for Fortigate and FortiAuthenticator

Vulnerability 1 (FortiAuthenticator)

A vulnerability concerning improper access control (CWE-284) in FortiAuthenticator could allow an unauthenticated attacker to execute unauthorised code or commands.

This can happen because the attacker sends specially crafted requests to the system, where the access controls are not correctly enforced. This allows someone without a valid login to perform actions that are normally intended only for authorised users.

Vulnerability 2 (FortiGate – FortiOS / CAPWAP daemon)

An Out-of-Bounds Write vulnerability (CWE-787) in the CAPWAP daemon of FortiOS may allow an attacker with control of an authenticated FortiAP, FortiExtender, or FortiSwitch device to obtain execution privileges on the FortiGate.

By exploiting this flaw, which allows the attacker to write outside the normal memory limits, they can potentially execute their own code on the FortiGate.

Take action

Customers who enjoy our Managed Security services are already aware and patched.

If you want to get started yourself, these are the procedures:

FortiAuthenticator – CVE-2026-44277

FortiAuthenticator 8.0 8.0.0 – 8.0.2 Upgrade to 8.0.3 or higher
FortiAuthenticator 6.6 6.6.0 – 6.6.8 Upgrade to 6.6.9 or higher
FortiAuthenticator 6.5 6.5.0 – 6.5.6 Upgrade to 6.5.7 or higher

Attention: During the upgrade, there will be approximately 30 minutes of impact on authentications (FSSO / RADIUS / …).Source)

Fortigate – CVE-2025-53844

FortiOS 7.6 7.6.0 – 7.6.3 Upgrade to 7.6.4 or higher
FortiOS 7.4 7.4.0 – 7.4.8 Upgrade to 7.4.9 or higher
FortiOS 7.2 7.2.0 – 7.2.11 Upgrade to 7.2.12 or higher

Impact: If you have a 70G/90G, it's possible that you will lose SSL VPN functionality through the upgrade.

```config global
config system global
set wireless-controller disable
end

**Post-Change Configuration Validation**
show full | grep wireless-controller
set wireless-controller disable
set wireless-controller-port 5246

show full | grep fortiextender
set fortiextender disable
set fortiextender-data-port 25246
set fortiextender-discovery-lockdown disable
set fortiextender-provision-on-authorization disable
set fortiextender-vlan-mode disable
```

This workaround has no impact (unless a FortiAP or FortiExtender is being used)

Need help?

Contact us to fix this problem for you. You can do this by mail at support@vanroey.be or count: 014 470 605. You can also have a create a ticket.

Can't create tickets? Ask here to get an account. If our Engineer needs to remotely control your PC, he or she will ask you to run this software .

Receive our newsletter including invitations to events & interesting industry news!

Receive alerts from current CVEs and tips to remedy them!

By registering, you agree to our privacy policy.

As we prepare for the Dynamate rebrand & merger, you can immerse yourself in, amongst other things,. AI, Cybersecurity, Business Applications...