FORTINET has released patches for eight vulnerabilities in its products, including significant authentication issues in FortiWeb and FortiManager. The CVE-2026-26035 vulnerability in FortiWeb allows unauthenticated remote attackers to access the GUI/CLI using any username when a specific wildcard setting is enabled. The CVE-2026-70468 vulnerability in FortiManager enables attackers to impersonate managed FortiGate devices if certain conditions are met.
Additionally, a critical buffer overflow in FortiClient for Windows (CVE-2026-70465) could allow code execution via manipulated DNS responses. Other medium- and low-severity flaws in FortiWeb WAF, FortiOS, and FortiSIEM were also addressed. Fortinet has not reported any exploitation of these vulnerabilities in the wild.