Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fortinet Patches Critical Auth Bypass in FortiWeb, FortiManager, FortiClient
August 13, 2026
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
August 13, 2026
Beacon CRM confirms full database theft after AWS access key breach
August 13, 2026
Home/CyberSecurity News/Fortinet Patches Critical Auth Bypass in FortiWeb, FortiManager, FortiClient
CyberSecurity News

Fortinet Patches Critical Auth Bypass in FortiWeb, FortiManager, FortiClient

Key Takeaways Fortinet has released critical patches for multiple authentication bypass and code execution vulnerabilities across its FortiWeb, FortiManager, and FortiClient product lines. The most...

Sarah simpson
Sarah simpson
August 13, 2026 4 Min Read
2 0

Key Takeaways

  • Fortinet has released critical patches for multiple authentication bypass and code execution vulnerabilities across its FortiWeb, FortiManager, and FortiClient product lines.
  • The most severe flaw, CVE-2026-26035 in FortiWeb, could allow unauthenticated remote attackers to gain administrative control.
  • Another significant vulnerability, CVE-2026-70468 in FortiManager, enables the impersonation of managed FortiGate devices.
  • Organizations are strongly advised to apply these updates immediately due to the critical nature of the affected systems and the ease of exploitation for some vulnerabilities.

Fortinet Addresses Critical Authentication Bypass and Code Execution Flaws

Fortinet has issued urgent security updates to address a series of high-severity vulnerabilities impacting its FortiWeb, FortiManager, and FortiClient offerings. The patches target critical authentication bypass issues and a remote code execution flaw, prompting a strong recommendation for immediate action from administrators.

Table Of Content

  • Key Takeaways
  • Fortinet Addresses Critical Authentication Bypass and Code Execution Flaws
  • FortiWeb Authentication Bypass (CVE-2026-26035)
  • FortiManager Authentication Bypass (CVE-2026-70468)
  • FortiClient for Windows Buffer Overflow (CVE-2026-70465)
  • What You Should Do

FortiWeb Authentication Bypass (CVE-2026-26035)

The most critical vulnerability, identified as CVE-2026-26035, resides within the login mechanism of FortiWeb, Fortinet’s web application firewall. This flaw carries a CVSS score ranging from 8.8 to 9.8, underscoring its severe potential for exploitation.

According to Fortinet’s advisory, the vulnerability is an improper authentication issue (CWE-287). It manifests when a FortiWeb administrator account is configured to use Remote RADIUS Type authentication with the “wildcard” setting enabled. This specific, non-default configuration can lead the appliance to incorrectly match any username provided by an attacker against a defined administrator group on the remote authentication server.

The practical implication is profound: a remote, unauthenticated attacker could “log in to the FortiWeb GUI/CLI with a random username and password,” as explained by Fortinet. This means attackers do not need to possess or guess valid credentials, as the flawed authentication logic facilitates unauthorized administrative access to the web application firewall.

A broad spectrum of FortiWeb versions is affected, including 8.0.0 through 8.0.2, 7.6.0 through 7.6.6, 7.4.0 through 7.4.11, 7.2.0 through 7.2.12, and the 7.0.x branch. Fortinet has released fixes in FortiWeb 8.0.3, 7.6.7, 7.4.12, and 7.2.13. Organizations still utilizing the legacy 7.0 line are advised to seek guidance from Fortinet support channels, as no direct patch has been specified for this branch.

For situations where immediate patching is not feasible, Fortinet has provided a straightforward workaround: disable the “wildcard” setting on Remote Type administrator accounts. This can be done via the GUI under System > Administrators or through the CLI by executing “set wildcard disable” within the config system admin context.

As of the advisory’s publication, Fortinet has not detected active exploitation of this vulnerability in the wild. However, given the low complexity required for an attack, this status could change rapidly.

FortiManager Authentication Bypass (CVE-2026-70468)

A separate, high-impact vulnerability has been patched in FortiManager, Fortinet’s centralized management platform for FortiGate firewalls. This flaw, tracked as CVE-2026-70468, is categorized as an authentication bypass via an alternate path or channel (CWE-288) and has a CVSS v3.1 score of 8.1.

The vulnerability stems from a weakness in the FGFM protocol, which FortiManager uses for communication with managed FortiGate devices. Exploitation of this flaw requires a specific CLI configuration option along with a valid certificate. If these conditions are met, an attacker could impersonate any FortiGate device managed by the FortiManager instance, potentially enabling the manipulation of firewall policies across the entire network.

Affected versions include FortiManager and FortiManager Cloud 7.6.1, 7.4.3 through 7.4.5, and 7.2.5 through 7.2.9. Corrective updates are available in versions 7.6.2, 7.4.6, and 7.2.10, respectively.

FortiClient for Windows Buffer Overflow (CVE-2026-70465)

Completing this round of critical updates, Fortinet also addressed a high-severity buffer overflow vulnerability in FortiClient for Windows, identified as CVE-2026-70465. This classic buffer copy flaw could allow an unauthenticated attacker, positioned to intercept or spoof DNS responses, to execute arbitrary code on a targeted endpoint. This is achieved by sending specially crafted network packets.

FortiClient Windows versions 7.4.0 through 7.4.3 and 7.2.0 through 7.2.11 are impacted by this vulnerability. Fixed versions are available in releases above 7.4.3 and 7.2.11.

Considering Fortinet’s history as a frequent target for both opportunistic and state-sponsored threat actors, security teams overseeing FortiWeb, FortiManager, or FortiClient deployments must prioritize these updates as essential security measures rather than routine maintenance.

What You Should Do

  • Immediately Apply Patches: Update FortiWeb to versions 8.0.3, 7.6.7, 7.4.12, or 7.2.13. For FortiManager/FortiManager Cloud, upgrade to 7.6.2, 7.4.6, or 7.2.10. For FortiClient Windows, update to versions above 7.4.3 and 7.2.11.
  • Consult Support for Legacy FortiWeb: If running FortiWeb 7.0.x, contact Fortinet support for specific guidance as no direct patch has been listed.
  • Implement Workarounds (FortiWeb CVE-2026-26035): If immediate patching of FortiWeb is not possible, disable the “wildcard” setting for Remote Type administrator accounts via the GUI (System > Administrators) or CLI (config system admin then set wildcard disable).
  • Review Configurations: Verify that FortiWeb administrator accounts using Remote RADIUS Type authentication do not have the “wildcard” setting enabled unless absolutely necessary and understood.
  • Monitor for Exploitation: Remain vigilant for any indicators of compromise or attempts to exploit these vulnerabilities, especially for CVE-2026-26035 due to its low attack complexity.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
North Korean IT Workers Impersonate Employees Using Forged IDs
August 13, 2026
CISA Warns of Critical Windows Ancillary Function Driver Zero-Day Exploited in Attacks
August 13, 2026
Likho Stealer’s New Toolkit Steals Telegram Sessions and Records Conversations
August 13, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us