Fortinet announced the release of patches for eight vulnerabilities affecting its product line. These updates address various security issues, ranging from high-severity authentication flaws to medium and low-severity defects across several platforms.
One of the critical vulnerabilities, CVE-2026-26035, was found in FortiWeb. This improper authentication issue could be exploited by a remote, unauthenticated attacker to log into the FortiWeb GUI/CLI using a random username and password. The flaw specifically affects deployments where the wildcard setting for administrator accounts is enabled, a non-default configuration. Fortinet has released patches for FortiWeb versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13, and recommends disabling the wildcard setting as a workaround.
Another high-severity vulnerability, CVE-2026-70468, impacts FortiManager. This authentication bypass issue allows remote attackers to impersonate any FortiGate device managed by FortiManager. Exploitation requires a specific CLI option to be set and for the attacker to possess a valid certificate.
Fortinet also patched CVE-2026-70465, a high-severity buffer overflow bug in FortiClient for Windows. This vulnerability could enable unauthenticated attackers to execute arbitrary code by modifying or crafting DNS responses. Furthermore, the company resolved medium- and low-severity security defects in FortiWeb WAF, FortiOS, and FortiSIEM, and published an advisory regarding CVE-2026-49975, which concerns the HTTP/2 Bomb attack affecting Apache HTTP Server. Fortinet has not indicated that any of these vulnerabilities are currently being exploited in the wild.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Fortinet released patches for eight vulnerabilities, including high-severity authentication bypass issues in FortiWeb and FortiManager. These flaws could allow unauthorized access or device impersonation, impacting network security for users of these products.