Fortinet has released patches for several critical authentication vulnerabilities affecting its FortiWeb, FortiManager, and FortiClient products. Administrators are strongly advised to apply these updates promptly due to the potential risks associated with these flaws.
FortiWeb Vulnerability (CVE-2026-26035)
The most severe of these vulnerabilities, identified as CVE-2026-26035, resides in FortiWeb’s login mechanism. This flaw, rated with a CVSS score between 8.8 and 9.8, is an improper authentication issue (CWE-287) that occurs when a FortiWeb administrator account is configured for Remote RADIUS Type authentication with the “wildcard” setting enabled. In this configuration, the appliance may match any username on the remote authentication server against a defined admin group, potentially allowing a remote, unauthenticated attacker to access the FortiWeb GUI/CLI using arbitrary credentials.
Affected versions include FortiWeb 8.0.0 through 8.0.2, 7.6.0 through 7.6.6, 7.4.0 through 7.4.11, 7.2.0 through 7.2.12, and the 7.0.x branch. Fortinet has addressed this issue in FortiWeb versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. Organizations using the 7.0.x branch should consult Fortinet support for guidance, as no fixed version has been specified for this branch.
As a temporary mitigation, administrators can disable the wildcard setting on Remote Type administrator accounts via the GUI under System > Administrators or by executing “set wildcard disable” in the CLI under config system admin.
FortiManager Vulnerability (CVE-2026-70468)
Another significant vulnerability, CVE-2026-70468, affects FortiManager, Fortinet’s centralized management platform for FortiGate firewalls. This authentication bypass issue (CWE-288) has a CVSS v3.1 score of 8.1 and arises from a weakness in the FGFM protocol used for communication between FortiManager and managed FortiGate devices. Exploitation requires a specific CLI configuration and a valid certificate, potentially allowing an attacker to impersonate any managed FortiGate device and manipulate firewall policies.
Impacted versions include FortiManager and FortiManager Cloud 7.6.1, 7.4.3 through 7.4.5, and 7.2.5 through 7.2.9. Fortinet has released fixes in versions 7.6.2, 7.4.6, and 7.2.10, respectively.
FortiClient Vulnerability (CVE-2026-70465)
Additionally, Fortinet has patched a high-severity buffer overflow vulnerability in FortiClient for Windows, designated as CVE-2026-70465. This classic buffer copy flaw (CWE-120) could enable an unauthenticated attacker to execute arbitrary code on a targeted endpoint via crafted network packets. The vulnerability affects FortiClient Windows versions 7.4.0 through 7.4.3 and 7.2.0 through 7.2.11.
Given Fortinet’s history as a target for both opportunistic and state-sponsored threat actors, it is imperative for security teams managing FortiWeb, FortiManager, or FortiClient to prioritize these updates to mitigate potential exploitation risks.
These vulnerabilities underscore the critical importance of regular software updates and vigilant configuration management in maintaining the security of network infrastructure. Organizations should not only apply patches promptly but also review their authentication configurations to prevent similar issues in the future.