Patch released FortiWeb auth-bypass FortiManager Fortinet network-edge
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
CVE Tools coverage
Fortinet has released updates addressing eight vulnerabilities across its network security portfolio, prioritizing high-severity authentication defects in FortiWeb and FortiManager. In FortiWeb, CVE-2026-26035 enables unauthenticated remote attackers to gain GUI/CLI access via random credentials when specific non-default wildcard administrator settings are active; this flaw is corrected in versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. Concurrently, CVE-2026-70468 allows remote impersonation of managed FortiGate devices within FortiManager under specific CLI configurations. The release also resolves a high-severity buffer overflow in FortiClient for Windows (CVE-2026-70465) and various lower-severity issues in FortiSIEM and FortiOS.