Fortinet Patches Critical FortiWeb Auth Bypass, CVSS 9.8
CVE-2026-26035 in FortiWeb lets unauthenticated attackers log in with any credentials — CVSS 9.8. FortiManager also gets a CVSS 8.1 auth bypass fix this cycle.
FortiWeb first. CVE-2026-26035, CVSS 9.8, critical. Improper authentication (CWE-287) in Fortinet’s FortiWeb WAF lets a remote unauthenticated attacker log in to the management GUI or CLI using any arbitrary username and password. Exploitation in the wild: unconfirmed as of publication — treat accordingly.
Affected versions — FortiWeb 7.0.x through 8.0.x:
| Branch | Affected range |
|---|---|
| FortiWeb 7.0 | 7.0.0 – 7.0.12 |
| FortiWeb 7.2 | 7.2.0 – 7.2.12 |
| FortiWeb 7.4 | 7.4.0 – 7.4.11 |
| FortiWeb 7.6 | 7.6.0 – 7.6.6 |
| FortiWeb 8.0 | 8.0.0 – 8.0.2 |
Fortinet advisory FG-IR-26-158 lists the patched builds. If immediate upgrade is not possible: restrict management interface access to trusted subnets and disable any internet-facing admin access — that buys time, it is not a fix.
The threat context: perimeter appliances are a reliable path from “advisory released” to “actively exploited.” FortiGate and FortiOS flaws have been weaponized by state-sponsored actors and ransomware crews within days of disclosure. A CVSS 9.8 auth bypass on an internet-facing security device is a first-tier patch priority regardless of exploitation status.
FortiManager — CVE-2026-70468, CVSS 8.1
CVE-2026-70468, CVSS 8.1, high. Authentication bypass via alternate path or channel (CWE-288). Affects on-premises FortiManager and FortiManager Cloud:
| Variant | Affected range |
|---|---|
| FortiManager | 7.2.5 – 7.2.9 |
| FortiManager | 7.4.3 – 7.4.5 |
| FortiManager | 7.6.1 |
| FortiManager Cloud | 7.2.5 – 7.2.9 |
| FortiManager Cloud | 7.4.3 – 7.4.5 |
| FortiManager Cloud | 7.6.1 |
Advisory: FG-IR-26-160. Exploitation: unconfirmed.
FortiManager is the central management plane for FortiGate deployments — the system that holds configs, credentials, and policy for every managed device in an environment. A prior FortiManager zero-day, CVE-2024-47575, was mass-exploited by nation-state actors before most defenders had a patch window. The risk profile for management-plane auth bypasses is categorically worse than the CVSS score alone suggests.
Lower-priority advisories in the same batch
- CVE-2026-71407 (FortiOS 7.6.1–7.6.6, CVSS 5.6, medium): Stack buffer overflow in the WAD daemon via crafted sockets. Exploitable only when explicit proxy with Kerberos authentication and SOCKS is enabled. Unauthenticated path.
- CVE-2026-71408 (FortiOS 7.2–7.6 across multiple branches, CVSS 5.3, medium): Resource exhaustion leading to denial of service.
Patch these on your normal cycle unless the condition for CVE-2026-71407 matches your deployment (explicit proxy + Kerberos + SOCKS — if so, elevate it).
What to do
- FortiWeb — Identify deployed versions. Upgrade per FG-IR-26-158. No upgrade window yet: firewall management access to known-good subnets, disable internet-facing admin paths.
- FortiManager — Upgrade per FG-IR-26-160. Management interfaces should not be internet-accessible regardless of patch status — if they are, fix that now independent of the patch.
- FortiOS (medium-severity) — Patch on your standard cycle per the linked advisories.
Related: August was a heavy patch month across the board — see the August 2026 Patch Tuesday roundup and Cisco ASA/FTD CVE-2026-20349 KEV addition for perimeter device context.
- [ CRITICAL ] CVE-2026-26035 FortiWeb Authentication Bypass Allows Unauthenticated Login
- [ HIGH ] CVE-2026-70468 FortiManager Authentication Bypass via Alternate Path
Found this useful? Share it.


