Breaking
SecurityDeveloping Story

Fortinet's Patch Wave Targets Authentication Gaps

Fortinet resolves eight flaws, including high-severity authentication bugs in FortiWeb and FortiManager.

··1 hour ago·2 min read
Matrix movie still
Photo by Markus Spiske on Unsplash

Fortinet on Wednesday announced patches for eight vulnerabilities across its product lineup, spotlighting high-severity authentication flaws in FortiWeb and FortiManager that could let remote attackers bypass security controls.

FortiWeb's Wildcard Authentication Bypass

The FortiWeb issue, tracked as CVE-2026-26035, stems from an improper authentication mechanism that surfaces when deployments use specific, non-default settings. A remote, unauthenticated attacker could exploit the flaw “to log in to the FortiWeb GUI/CLI with a random username and password,” according to Fortinet's advisory.

At the heart of the weakness is the wildcard setting for administrator accounts, which is disabled by default. When enabled, the system matches any username on a remote server against the Remote User account, potentially granting access to admin functions without proper credentials.

“When wildcard is enabled, and if you have defined a group name in the Admin User Group (User > User Group > Admin Group), then the system will match the users on the remote server whose group name value is the same as you defined,” Fortinet explains.

Fortinet has addressed the bug in FortiWeb versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. As a workaround, the company recommends disabling the wildcard setting.

FortiManager Impersonation Risk

In FortiManager, the authentication bypass tracked as CVE-2026-70468 allows remote attackers to impersonate any FortiGate device managed by the platform. This requires a specific CLI option to be set and the attacker to possess a valid certificate, adding layers of complexity to exploitation.

While not listed as critical, the bypass could enable unauthorized management access, putting network configurations and security policies at risk.

Buffer Overflow in FortiClient

Fortinet also fixed a high-severity buffer overflow vulnerability (CVE-2026-70465) affecting FortiClient for Windows. The flaw could allow unauthenticated attackers who can modify or craft DNS responses to execute arbitrary code on affected systems.

This vulnerability highlights the importance of securing DNS integrity, as a well-crafted response could trigger code execution in the context of the logged-in user.

Additional Patches Across the Portfolio

Beyond these high-profile fixes, the vendor resolved medium- and low-severity defects in FortiWeb WAF, FortiOS, and FortiSIEM. Fortinet also published an advisory detailing the impact of CVE-2026-49975, the HTTP/2 Bomb attack affecting Apache HTTP Server, a separate but notable security concern.

No Reports of Active Exploitation

Fortinet makes no mention of any of these vulnerabilities being exploited in the wild. Still, the company urges users to review its PSIRT advisories page for detailed guidance and apply patches promptly.

Why It Matters

The breadth of this patch bundle underscores the persistent challenge of authentication flaws in network management tools. Even with no confirmed exploits, the nature of these vulnerabilities—especially the authentication bypass in FortiManager—suggests that organizations with these products exposed to the internet should treat upgrades as a high priority. Attackers often move quickly once details are public, and the absence of active exploitation today doesn't guarantee safety tomorrow.

#fortinet#cve-2026-26035#cve-2026-70468#authentication bypass#buffer overflow#patch tuesday

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories