Fortinet patches eight vulnerabilities, including FortiWeb and FortiManager authentication flaws
This digest was compiled by AI from multiple sources — links to the originals are below.

Fortinet on Wednesday announced patches for eight vulnerabilities across its products, including high-severity authentication bugs in FortiWeb and FortiManager. The FortiWeb issue, CVE-2026-26035, allows remote unauthenticated login when a wildcard setting is enabled; the FortiManager issue, CVE-2026-70468, lets attackers impersonate FortiGate devices under specific CLI and certificate conditions. Fortinet said it is unaware of any in-the-wild exploitation.
The FortiWeb Authentication Flaw
Fortinet resolved an improper authentication issue in FortiWeb deployments configured with a specific, non-default setting. Tracked as CVE-2026-26035, the flaw allows a remote, unauthenticated attacker to log in to the FortiWeb GUI or CLI with a random username and password. The bug is tied to the wildcard setting for administrator accounts, which is disabled by default; when enabled, FortiWeb matches any remote username against the Remote User account if an Admin User Group name is defined. Patches are available in FortiWeb versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. Fortinet recommends disabling the wildcard setting as a workaround.
Additional Patches and Advisory
The FortiManager authentication bypass, CVE-2026-70468, lets remote attackers impersonate any FortiGate device managed by FortiManager, provided a specific CLI option is set and the attacker holds a valid certificate. Fortinet also fixed a high-severity buffer overflow in FortiClient for Windows, CVE-2026-70465, enabling unauthenticated attackers who can craft or modify DNS responses to execute arbitrary code. On Wednesday the company resolved medium- and low-severity defects in FortiWeb WAF, FortiOS, and FortiSIEM, and published an advisory on CVE-2026-49975, the HTTP/2 Bomb attack affecting Apache HTTP Server. Fortinet made no mention of active exploitation for any of the eight vulnerabilities.
What's Next
Fortinet is directing administrators to update affected FortiWeb, FortiManager, FortiClient, FortiOS, and FortiSIEM versions according to its PSIRT advisories. It remains unclear whether any of the eight vulnerabilities were targeted before patches were released, or how widely non-default wildcard and CLI options are enabled across deployments.
1 source
Fortinet patches eight vulnerabilities, including FortiWeb and FortiManager authentication flaws



