Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance.

Fortinet patches

Fortinet on Wednesday announced patches for eight vulnerabilities across its products, including high-severity authentication bugs in FortiWeb and FortiManager.

In FortiWeb, the company resolved an improper authentication issue impacting deployments configured with specific, non-default settings.

A remote, unauthenticated attacker could exploit the flaw, tracked as CVE-2026-26035, “to log in to the FortiWeb GUI/CLI with a random username and password,” Fortinet explains.

The weakness is associated with the wildcard setting for administrator accounts, which is disabled by default. When it is enabled, the system will match any username on a remote server with the Remote User account.

“When wildcard is enabled, and if you have defined a group name in the Admin User Group (User > User Group > Admin Group), then the system will match the users on the remote server whose group name value is the same as you defined,” Fortinet explains.

CVE-2026-26035 was patched in FortiWeb versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. As a workaround, the company recommends disabling the wildcard setting.

Advertisement. Scroll to continue reading.

The FortiManager vulnerability, tracked as CVE-2026-70468, is an authentication bypass issue that allows remote attackers to impersonate any FortiGate device managed by FortiManager. It requires a specific CLI option to be set and for the attacker to have a valid certificate.

Fortinet also patched a high-severity buffer overflow bug (CVE-2026-70465) in FortiClient for Windows that could allow unauthenticated attackers who can modify or craft DNS responses to execute arbitrary code.

On Wednesday, the company also resolved medium- and low-severity security defects in FortiWeb WAF, FortiOS, and FortiSIEM, and published an advisory detailing the impact of CVE-2026-49975, the HTTP/2 Bomb attack affecting Apache HTTP Server.

Fortinet makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found on the company’s PSIRT advisories page.

Related: Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

Related: Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

Related: SharePoint Vulnerability Exploited Shortly After PoC Release

Related: Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

John Opala has joined Ralph Lauren as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.