← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Fortinet Patches High-Severity Authentication Flaws in FortiWeb and FortiManager

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Fortinet patched eight vulnerabilities across its products.
  • CVE-2026-26035 in FortiWeb allowed unauthenticated login with specific settings.
  • CVE-2026-70468 in FortiManager allowed FortiGate device impersonation.
  • A high-severity buffer overflow in FortiClient for Windows was also patched.

Fortinet Addresses Multiple Vulnerabilities

Fortinet announced the release of patches for eight vulnerabilities affecting its product line. These updates address various security issues, ranging from high-severity authentication flaws to medium and low-severity defects across several platforms.

High-Severity FortiWeb Authentication Bypass

One of the critical vulnerabilities, CVE-2026-26035, was found in FortiWeb. This improper authentication issue could be exploited by a remote, unauthenticated attacker to log into the FortiWeb GUI/CLI using a random username and password. The flaw specifically affects deployments where the wildcard setting for administrator accounts is enabled, a non-default configuration. Fortinet has released patches for FortiWeb versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13, and recommends disabling the wildcard setting as a workaround.

FortiManager Impersonation Flaw

Another high-severity vulnerability, CVE-2026-70468, impacts FortiManager. This authentication bypass issue allows remote attackers to impersonate any FortiGate device managed by FortiManager. Exploitation requires a specific CLI option to be set and for the attacker to possess a valid certificate.

Additional Patches and Advisories

Fortinet also patched CVE-2026-70465, a high-severity buffer overflow bug in FortiClient for Windows. This vulnerability could enable unauthenticated attackers to execute arbitrary code by modifying or crafting DNS responses. Furthermore, the company resolved medium- and low-severity security defects in FortiWeb WAF, FortiOS, and FortiSIEM, and published an advisory regarding CVE-2026-49975, which concerns the HTTP/2 Bomb attack affecting Apache HTTP Server. Fortinet has not indicated that any of these vulnerabilities are currently being exploited in the wild.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Fortinet released patches for eight vulnerabilities, including high-severity authentication bypass issues in FortiWeb and FortiManager. These flaws could allow unauthorized access or device impersonation, impacting network security for users of these products.