Fortinet on Wednesday announced patches for eight vulnerabilities across its products, including high-severity authentication bugs in FortiWeb and FortiManager.
In FortiWeb, the company resolved an improper authentication issue impacting deployments configured with specific, non-default settings.
A remote, unauthenticated attacker could exploit the flaw, tracked as CVE-2026-26035, “to log in to the FortiWeb GUI/CLI with a random username and password,” Fortinet explains.
The weakness is associated with the wildcard setting for administrator accounts, which is disabled by default. When it is enabled, the system will match any username on a remote server with the Remote User account.
“When wildcard is enabled, and if you have defined a group name in the Admin User Group (User > User Group > Admin Group), then the system will match the users on the remote server whose group name value is the same as you defined,” Fortinet explains.
CVE-2026-26035 was patched in FortiWeb versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. As a workaround, the company recommends disabling the wildcard setting.
The FortiManager vulnerability, tracked as CVE-2026-70468, is an authentication bypass issue that allows remote attackers to impersonate any FortiGate device managed by FortiManager. It requires a specific CLI option to be set and for the attacker to have a valid certificate.
Fortinet also patched a high-severity buffer overflow bug (CVE-2026-70465) in FortiClient for Windows that could allow unauthenticated attackers who can modify or craft DNS responses to execute arbitrary code.
On Wednesday, the company also resolved medium- and low-severity security defects in FortiWeb WAF, FortiOS, and FortiSIEM, and published an advisory detailing the impact of CVE-2026-49975, the HTTP/2 Bomb attack affecting Apache HTTP Server.
Fortinet makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found on the company’s PSIRT advisories page.
Related: Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Related: Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
Related: SharePoint Vulnerability Exploited Shortly After PoC Release
Related: Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws