Fortinet Authentication Flaw Patches | FortiWeb FortiManager Security Fixes
Fortinet released updates to address eight security flaws across its product portfolio, including critical authentication issues in FortiWeb and FortiManager.
Critical Authentication Flaws in FortiWeb and FortiManager
Fortinet released updates on Wednesday to address eight security flaws across its product portfolio, including critical authentication issues in FortiWeb and FortiManager. The vulnerabilities, which could enable unauthorized access or system compromise, were resolved through firmware and software patches.
CVE-2026-26035 in FortiWeb
A flaw in FortiWeb, designated CVE-2026-26035, involves a misconfigured authentication mechanism that affects deployments using non-default settings. The vulnerability arises from the wildcard option for administrator accounts, which is disabled by default. When enabled, this feature allows the system to match any username from a remote server with the Remote User account. If a group name is defined in the Admin User Group configuration, the system may authenticate users whose remote server group names align with the specified group. This could permit an unauthenticated attacker to gain access to the FortiWeb graphical user interface or command-line interface using arbitrary credentials. Patches for this issue are included in FortiWeb versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. As a temporary mitigation, users are advised to disable the wildcard setting.
CVE-2026-70468 in FortiManager
Another critical flaw, CVE-2026-70468, impacts FortiManager and allows remote attackers to bypass authentication by impersonating managed FortiGate devices. Exploitation requires a specific CLI command to be enabled and the presence of a valid certificate. This vulnerability could enable attackers to manipulate device configurations or execute unauthorized commands.
CVE-2026-70465 in FortiClient
A separate high-severity buffer overflow vulnerability, CVE-2026-70465, was identified in FortiClient for Windows. This flaw could be exploited by unauthenticated attackers who intercept or manipulate DNS responses to execute arbitrary code on affected systems.
Other Vulnerabilities Addressed
In addition to these critical issues, Fortinet addressed medium- and low-severity flaws in FortiWeb WAF, FortiOS, and FortiSIEM. The company also issued an advisory regarding CVE-2026-49975, a vulnerability affecting Apache HTTP Server that enables HTTP/2 protocol-based attacks. No evidence of active exploitation for any of the patched vulnerabilities has been reported.
Fortinet’s PSIRT advisories provide further details on the affected products, mitigation strategies, and patching instructions. The updates highlight the ongoing need for organizations to apply security patches promptly, particularly for systems handling authentication and network traffic. The vulnerabilities underscore the risks associated with misconfigured settings and the importance of maintaining up-to-date security controls.
Conclusion
The updates highlight the ongoing need for organizations to apply security patches promptly, particularly for systems handling authentication and network traffic. The vulnerabilities underscore the risks associated with misconfigured settings and the importance of maintaining up-to-date security controls.
