Fortinet has released fixes for a set of authentication flaws in its FortiWeb, FortiManager, and FortiClient products. It warns admins to update quickly because these systems are sensitive.
The severe one, known as CVE-2026-26035, is found in FortiWeb’s login system. It has a CVSS score between 8.8 and 9.8 based on the source, showing how easily it can be misused with a bad setup.
According to Fortinet’s advisory, the flaw is an improper authentication issue (CWE-287) that surfaces when a FortiWeb administrator account is configured for Remote RADIUS Type authentication with the “wildcard” setting turned on.
With that special setup, the device can match any username on the remote server with an admin group. This lets a remote attacker who isn’t logged in “access the FortiWeb GUI/CLI using any username and password,” according to Fortinet.
An attacker doesn’t need to know or guess the right login details, because the faulty matching system does it for them, giving them control of the web application firewall.
The bug affects many FortiWeb versions, including 8.0.0 to 8.0.2, 7.6.0 to 7.6.6, 7.4.0 to 7.4.11, 7.2.0 to 7.2.12, and the old 7.0.x series.
Fortinet has sent out fixed versions in FortiWeb 8.0.3, 7.6.7, 7.4.12, and 7.2.13. Groups using the older 7.0 versions should talk to support for help because there is no fixed version for that group.
When you can’t patch right away, Fortinet suggests a simple fix: turn off the wildcard setting for Remote Type admin accounts. You can do this in the GUI under System > Administrators or by typing “set wildcard disable” in the CLI under config system admin.
As of the advisory’s publication,Fortinet has not seen any attacks taking advantage of this issue so far, but because the attack is easy to do, that may change soon.
FortiManager Vulnerability
A different but also worrying flaw was fixed in FortiManager. This is the main tool that many companies use to set up and watch over groups of FortiGate firewalls.
Tracked as CVE-2026-70468, this issue is seen as an authentication bypass using a different method (CWE-288). It has a CVSS v3.1 score of 8.1. The problem comes from a weakness in the FGFM protocol that FortiManager uses to talk to FortiGate devices. To exploit it, a special CLI setting and a valid certificate are needed.
If those conditions are true, a hacker could pretend to be any FortiGate device that the FortiManager controls, possibly changing firewall rules widely.
Affected versions are FortiManager and FortiManager Cloud 7.6.1, 7.4.3 to 7.4.5, and 7.2.5 to 7.2.9. Fixes are in 7.6.2, 7.4.6, and 7.2.10.
Fortinet has fixed a serious buffer overflow in FortiClient for Windows in this update. It is marked as CVE-2026-70465.
The old buffer copy flaw might allow an attacker who is not signed in to catch or fake DNS answers to run any code on a specific device using specially made network packets. This issue affects FortiClient versions 7.4.0 to 7.4.3 and 7.2.0 to 7.2.11.
Fortinet has been targeted many times by opportunistic and state-linked threat actors. Because of this, security teams using FortiWeb, FortiManager, or FortiClient should see these updates as important patches, not just regular maintenance.

InfoSecBulletin Cybersecurity for mankind
