www.securityweek.com 8/13/2026, 11:07:04 AM · external

Fortinet patches CVE-2026-26035 auth bypass in FortiWeb

Fortinet patches CVE-2026-26035 auth bypass in FortiWeb
CyberSIXT Evidence Panel

FORTINET has released patches for eight vulnerabilities in its products, including significant authentication issues in FortiWeb and FortiManager. The CVE-2026-26035 vulnerability in FortiWeb allows unauthenticated remote attackers to access the GUI/CLI using any username when a specific wildcard setting is enabled. The CVE-2026-70468 vulnerability in FortiManager enables attackers to impersonate managed FortiGate devices if certain conditions are met.

Additionally, a critical buffer overflow in FortiClient for Windows (CVE-2026-70465) could allow code execution via manipulated DNS responses. Other medium- and low-severity flaws in FortiWeb WAF, FortiOS, and FortiSIEM were also addressed. Fortinet has not reported any exploitation of these vulnerabilities in the wild.

View Primary Source Via www.securityweek.com

Article by CyberSIXT