Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
PatchFortiWebFortiManagerOur summary
Fortinet has released updates addressing eight vulnerabilities across its network security portfolio, prioritizing high-severity authentication defects in FortiWeb and FortiManager. In FortiWeb, CVE-2026-26035 enables unauthenticated remote attackers to gain GUI/CLI access via random credentials when specific non-default wildcard administrator settings are active; this flaw is corrected in versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. Concurrently, CVE-2026-70468 allows remote impersonation of managed FortiGate devices within FortiManager under specific CLI configurations. The release also resolves a high-severity buffer overflow in FortiClient for Windows (CVE-2026-70465) and various lower-severity issues in FortiSIEM and FortiOS.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.