Saturday , September 5 2026
FortiWeb

Fortinet Fixes Multiple Flaws in FortiWeb, FortiManager, and FortiClient

Fortinet has released fixes for a set of authentication flaws in its FortiWeb, FortiManager, and FortiClient products. It warns admins to update quickly because these systems are sensitive.

The severe one, known as CVE-2026-26035, is found in FortiWeb’s login system. It has a CVSS score between 8.8 and 9.8 based on the source, showing how easily it can be misused with a bad setup.

14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day online attack that affected devices...
Read More
14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Microsoft Reveals Project Zenith Windows PCs Able to Run 30B+ AI Models Locally

Microsoft has launched Project Zenith, a new Windows 11 experience for developers. It is made for powerful PCs that can...
Read More
Microsoft Reveals Project Zenith Windows PCs Able to Run 30B+ AI Models Locally

Google issues warning of new Chrome zero-day flaw exploited

Google has updated the Chrome browser to fix a serious security issue in the V8 engine and 11 other flaws....
Read More
Google issues warning of new Chrome zero-day flaw exploited

CrowdStrike’s ‘FalconFlank’ zero-day allows SYSTEM privileges

An unnamed security expert known as "Nightmare Eclipse" shared a CrowdStrike Falcon zero-day exploit called "FalconFlank." This tool allows hackers...
Read More
CrowdStrike’s ‘FalconFlank’ zero-day allows SYSTEM privileges

727,000 data exposes: French hospital fined €500,000

France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for not properly protecting the data...
Read More
727,000 data exposes: French hospital fined €500,000

153 Million Driver’s License Surfaced on Dark Web: FBI Starts Investigation

The FBI’s New Orleans field office has opened an investigation into the suspected source of more than 153 million driver’s...
Read More
153 Million Driver’s License Surfaced on Dark Web: FBI Starts Investigation

Google Unveils Gemini 3.8 Flash Cyber to Identify and Auto-Patch Security Flaws

Google has launched Gemini 3.8, its newest model for reasoning and coding. It includes a special version named Gemini 3.8...
Read More
Google Unveils Gemini 3.8 Flash Cyber to Identify and Auto-Patch Security Flaws

SonicWall SMA1000 SSRF Hits 10, Exploiting CVE-2026-83548 

SonicWall unveiled advisory SNWLID-2026-0016 on September 1, 2026. It states that two SMA1000 flaws are being actively exploited. The main...
Read More
SonicWall SMA1000 SSRF Hits 10, Exploiting CVE-2026-83548 

Gartner
70% of SOCs Will Pilot AI Agents: Only 15% Will See Results

The market for AI SOC agents is early, crowded, and full of claims that haven't been tested in production. This Gartner...
Read More
Gartner  70% of SOCs Will Pilot AI Agents: Only 15% Will See Results

CVE-2026-62911
Nearly 22,000 Microsoft Exchange Servers are vulnerable to attack

Almost 22,000 Microsoft Exchange servers are online and still vulnerable to a flaw that lets attackers access all user mailboxes. Tracked...
Read More
CVE-2026-62911  Nearly 22,000 Microsoft Exchange Servers are vulnerable to attack

According to Fortinet’s advisory, the flaw is an improper authentication issue (CWE-287) that surfaces when a FortiWeb administrator account is configured for Remote RADIUS Type authentication with the “wildcard” setting turned on.

With that special setup, the device can match any username on the remote server with an admin group. This lets a remote attacker who isn’t logged in “access the FortiWeb GUI/CLI using any username and password,” according to Fortinet.

An attacker doesn’t need to know or guess the right login details, because the faulty matching system does it for them, giving them control of the web application firewall.

The bug affects many FortiWeb versions, including 8.0.0 to 8.0.2, 7.6.0 to 7.6.6, 7.4.0 to 7.4.11, 7.2.0 to 7.2.12, and the old 7.0.x series.

Fortinet has sent out fixed versions in FortiWeb 8.0.3, 7.6.7, 7.4.12, and 7.2.13. Groups using the older 7.0 versions should talk to support for help because there is no fixed version for that group.

When you can’t patch right away, Fortinet suggests a simple fix: turn off the wildcard setting for Remote Type admin accounts. You can do this in the GUI under System > Administrators or by typing “set wildcard disable” in the CLI under config system admin.

As of the advisory’s publication,Fortinet has not seen any attacks taking advantage of this issue so far, but because the attack is easy to do, that may change soon.

FortiManager Vulnerability

A different but also worrying flaw was fixed in FortiManager. This is the main tool that many companies use to set up and watch over groups of FortiGate firewalls.

Tracked as CVE-2026-70468, this issue is seen as an authentication bypass using a different method (CWE-288). It has a CVSS v3.1 score of 8.1. The problem comes from a weakness in the FGFM protocol that FortiManager uses to talk to FortiGate devices. To exploit it, a special CLI setting and a valid certificate are needed.

If those conditions are true, a hacker could pretend to be any FortiGate device that the FortiManager controls, possibly changing firewall rules widely.

Affected versions are FortiManager and FortiManager Cloud 7.6.1, 7.4.3 to 7.4.5, and 7.2.5 to 7.2.9. Fixes are in 7.6.2, 7.4.6, and 7.2.10.

Fortinet has fixed a serious buffer overflow in FortiClient for Windows in this update. It is marked as CVE-2026-70465.

The old buffer copy flaw might allow an attacker who is not signed in to catch or fake DNS answers to run any code on a specific device using specially made network packets. This issue affects FortiClient versions 7.4.0 to 7.4.3 and 7.2.0 to 7.2.11.

Fortinet has been targeted many times by opportunistic and state-linked threat actors. Because of this, security teams using FortiWeb, FortiManager, or FortiClient should see these updates as important patches, not just regular maintenance.

Check Also

Microsoft Exchange Server

CVE-2026-62911
Nearly 22,000 Microsoft Exchange Servers are vulnerable to attack

Almost 22,000 Microsoft Exchange servers are online and still vulnerable to a flaw that lets …