Fortinet Patches High-Severity Authentication Flaws in FortiWeb, FortiManager
TL;DR. Fortinet released patches for eight vulnerabilities, including critical authentication bugs in its FortiWeb and FortiManager products. - The FortiWeb flaw allowed unauthenticated remote logins with random credentials when specific settings were enabled. - FortiManager's vulnerability permitted remote attackers to impersonate FortiGate devices if a CLI option was set. - Fortinet also addressed a buffer overflow in FortiClient for Windows and other medium-to-low severity issues.
- Fortinet issued patches for eight vulnerabilities across its product line.
- A high-severity FortiWeb flaw (CVE-2026-26035) allowed unauthenticated remote access under specific configurations.
- Another high-severity bug in FortiManager (CVE-2026-70468) enabled FortiGate device impersonation by remote attackers.
- Additional patches addressed issues in FortiClient for Windows, FortiWeb WAF, FortiOS, and FortiSIEM.
- Fortinet reported no active exploits of these vulnerabilities in the wild.
Sources
- Fortinet Patches Authentication Flaws in FortiWeb and FortiManager — securityweek.com