Vulnerabilities

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance.

Fortinet on Wednesday announced patches for eight vulnerabilities across its products, including high-severity authentication bugs in FortiWeb and FortiManager.

In FortiWeb, the company resolved an improper authentication issue impacting deployments configured with specific, non-default settings.

A remote, unauthenticated attacker could exploit the flaw, tracked as CVE-2026-26035, “to log in to the FortiWeb GUI/CLI with a random username and password,” Fortinet explains.

The weakness is associated with the wildcard setting for administrator accounts, which is disabled by default. When it is enabled, the system will match any username on a remote server with the Remote User account.

“When wildcard is enabled, and if you have defined a group name in the Admin User Group (User > User Group > Admin Group), then the system will match the users on the remote server whose group name value is the same as you defined,” Fortinet explains.

CVE-2026-26035 was patched in FortiWeb versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. As a workaround, the company recommends disabling the wildcard setting.

Advertisement. Scroll to continue reading.

The FortiManager vulnerability, tracked as CVE-2026-70468, is an authentication bypass issue that allows remote attackers to impersonate any FortiGate device managed by FortiManager. It requires a specific CLI option to be set and for the attacker to have a valid certificate.

Fortinet also patched a high-severity buffer overflow bug (CVE-2026-70465) in FortiClient for Windows that could allow unauthenticated attackers who can modify or craft DNS responses to execute arbitrary code.

On Wednesday, the company also resolved medium- and low-severity security defects in FortiWeb WAF, FortiOS, and FortiSIEM, and published an advisory detailing the impact of CVE-2026-49975, the HTTP/2 Bomb attack affecting Apache HTTP Server.

Fortinet makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found on the company’s PSIRT advisories page.

Related: Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

Related: Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

Related: SharePoint Vulnerability Exploited Shortly After PoC Release

Related: Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

Related Content

Cybercrime

The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.

Malware & Threats

The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised.

Vulnerabilities

Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772.

Vulnerabilities

CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.

Artificial Intelligence

Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks.

Email Security

Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.

Vulnerabilities

The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.

Vulnerabilities

Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version