CVE Tools

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

SecurityWeekBy Ionut Arghire

PatchFortiWebFortiManager

Our summary

Fortinet has released updates addressing eight vulnerabilities across its network security portfolio, prioritizing high-severity authentication defects in FortiWeb and FortiManager. In FortiWeb, CVE-2026-26035 enables unauthenticated remote attackers to gain GUI/CLI access via random credentials when specific non-default wildcard administrator settings are active; this flaw is corrected in versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. Concurrently, CVE-2026-70468 allows remote impersonation of managed FortiGate devices within FortiManager under specific CLI configurations. The release also resolves a high-severity buffer overflow in FortiClient for Windows (CVE-2026-70465) and various lower-severity issues in FortiSIEM and FortiOS.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store