Fortinet's Patch Wave Targets Authentication Gaps
Fortinet resolves eight flaws, including high-severity authentication bugs in FortiWeb and FortiManager.
Fortinet on Wednesday announced patches for eight vulnerabilities across its product lineup, spotlighting high-severity authentication flaws in FortiWeb and FortiManager that could let remote attackers bypass security controls.
FortiWeb's Wildcard Authentication Bypass
The FortiWeb issue, tracked as CVE-2026-26035, stems from an improper authentication mechanism that surfaces when deployments use specific, non-default settings. A remote, unauthenticated attacker could exploit the flaw “to log in to the FortiWeb GUI/CLI with a random username and password,” according to Fortinet's advisory.
At the heart of the weakness is the wildcard setting for administrator accounts, which is disabled by default. When enabled, the system matches any username on a remote server against the Remote User account, potentially granting access to admin functions without proper credentials.
“When wildcard is enabled, and if you have defined a group name in the Admin User Group (User > User Group > Admin Group), then the system will match the users on the remote server whose group name value is the same as you defined,” Fortinet explains.
Fortinet has addressed the bug in FortiWeb versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. As a workaround, the company recommends disabling the wildcard setting.
FortiManager Impersonation Risk
In FortiManager, the authentication bypass tracked as CVE-2026-70468 allows remote attackers to impersonate any FortiGate device managed by the platform. This requires a specific CLI option to be set and the attacker to possess a valid certificate, adding layers of complexity to exploitation.
While not listed as critical, the bypass could enable unauthorized management access, putting network configurations and security policies at risk.
Buffer Overflow in FortiClient
Fortinet also fixed a high-severity buffer overflow vulnerability (CVE-2026-70465) affecting FortiClient for Windows. The flaw could allow unauthenticated attackers who can modify or craft DNS responses to execute arbitrary code on affected systems.
This vulnerability highlights the importance of securing DNS integrity, as a well-crafted response could trigger code execution in the context of the logged-in user.
Additional Patches Across the Portfolio
Beyond these high-profile fixes, the vendor resolved medium- and low-severity defects in FortiWeb WAF, FortiOS, and FortiSIEM. Fortinet also published an advisory detailing the impact of CVE-2026-49975, the HTTP/2 Bomb attack affecting Apache HTTP Server, a separate but notable security concern.
No Reports of Active Exploitation
Fortinet makes no mention of any of these vulnerabilities being exploited in the wild. Still, the company urges users to review its PSIRT advisories page for detailed guidance and apply patches promptly.
Why It Matters
The breadth of this patch bundle underscores the persistent challenge of authentication flaws in network management tools. Even with no confirmed exploits, the nature of these vulnerabilities—especially the authentication bypass in FortiManager—suggests that organizations with these products exposed to the internet should treat upgrades as a high priority. Attackers often move quickly once details are public, and the absence of active exploitation today doesn't guarantee safety tomorrow.
Sources
- SecurityWeek Original source
Continue Reading
Google Doc Credentials Leak Serves as a Cautionary Tale
A developer's habit of storing passwords in a shared Google Doc led to a search-indexed exposure of staging credentials.
SecurityNewUS Enlists Private Firms in Cybercrime Crackdown
A presidential memo lets vetted US companies run offensive cyber ops against foreign crime rings.
Unauthenticated SAP Flaw Earns Maximum CVSS Score
SAP ships urgent patches for Commerce Cloud and other critical flaws rated up to 10.0.