Fortinet fixes FortiWeb, FortiManager authentication flaws
Fortinet released patches for eight vulnerabilities, including two high-severity authentication flaws in FortiWeb and FortiManager that could allow unauthorized access and device impersonation.
Fortinet on Wednesday released patches for eight security flaws across its product line, including two high-severity authentication issues in FortiWeb and FortiManager that could allow unauthorized access and device impersonation.
The FortiWeb flaw, tracked as CVE-2026-26035, is an improper authentication issue that affects deployments where a non-default wildcard administrator setting is enabled. Fortinet explained: “When wildcard is enabled, and if you have defined a group name in the Admin User Group (User > User Group > Admin Group), then the system will match the users on the remote server whose group name value is the same as you defined.” With the wildcard option active, the system can match any username on a remote authentication server to the local Remote User account. Fortinet patched the defect in FortiWeb versions 8.0.3, 7.6.7, 7.4.12 and 7.2.13 and recommends disabling the wildcard option as a workaround until systems are updated.
The FortiManager vulnerability, CVE-2026-70468, is an authentication bypass that could allow a remote attacker to impersonate any FortiGate device managed by FortiManager. Exploitation requires a specific command-line interface option to be enabled and for the attacker to present a valid certificate. Fortinet updated the affected FortiManager builds and advised administrators to review CLI options and certificate handling to reduce exposure.
Fortinet also patched a high-severity buffer overflow in FortiClient for Windows, CVE-2026-70465. That defect could allow unauthenticated attackers who can modify or craft DNS responses to execute arbitrary code on vulnerable Windows endpoints. The company addressed additional medium- and low-severity flaws in FortiWeb WAF, FortiOS and FortiSIEM, and published an advisory that references CVE-2026-49975, the HTTP/2 “Bomb” attack affecting Apache HTTP Server.
Fortinet reported no evidence that any of the patched vulnerabilities have been exploited in the wild. The vendor urged customers to apply available updates promptly, disable non-default settings such as the FortiWeb wildcard administrator option where possible, review certificate and CLI configurations on FortiManager deployments, and consult the company’s PSIRT advisories for version-specific patch files and deployment guidance.
FortiWeb is Fortinet’s web application firewall for protecting web applications and APIs. FortiManager centralizes management for FortiGate firewalls and related devices. FortiClient provides endpoint protection for Windows systems. Administrators responsible for these products should verify patch availability, confirm backups, and follow change-management procedures before applying updates.








