Fortinet patches FortiWeb and FortiManager authentication flaws including CVE-2026-26035 and CVE-2026-70468

Fortinet released security fixes for authentication flaws in FortiWeb and FortiManager that could let attackers log in improperly or impersonate managed devices. The most serious issues are CVE-2026-26035 in FortiWeb, which can allow unauthenticated login with random credentials when the non-default wildcard admin setting is enabled, and CVE-2026-70468 in FortiManager, which can let a remote attacker impersonate any managed FortiGate if a specific CLI option is enabled and the attacker has a valid certificate. Fortinet also patched CVE-2026-70465, a FortiClient for Windows buffer overflow tied to crafted or modified DNS responses.
Why it matters: Organizations using Fortinet security and management products should review configurations and patch quickly, especially if they use the affected non-default settings. These bugs affect products that sit in sensitive security roles, so successful exploitation could give attackers powerful footholds or let them spoof trusted devices.

Sources

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
Ionut Arghire 2026.08.13 100% relevant
This article establishes a distinct Fortinet patch event centered on newly disclosed authentication vulnerabilities in FortiWeb and FortiManager, and it does not match an existing tracked story about a different Fortinet product or CVE.
← Back to all stories