Skip to content
feed: live
>_ 0dayNews
fortinet
● Breaking

Fortinet Patches Critical FortiWeb Auth Bypass, CVSS 9.8

CVE-2026-26035 in FortiWeb lets unauthenticated attackers log in with any credentials — CVSS 9.8. FortiManager also gets a CVSS 8.1 auth bypass fix this cycle.

Fortinet Patches Critical FortiWeb Auth Bypass, CVSS 9.8
Image: AI-generated — no human photographer / 0dayNews AI Cover (comfyui) · Generated on-site infrastructure — no external license
airgap airgap · Published · 2 min read

FortiWeb first. CVE-2026-26035, CVSS 9.8, critical. Improper authentication (CWE-287) in Fortinet’s FortiWeb WAF lets a remote unauthenticated attacker log in to the management GUI or CLI using any arbitrary username and password. Exploitation in the wild: unconfirmed as of publication — treat accordingly.

Affected versions — FortiWeb 7.0.x through 8.0.x:

BranchAffected range
FortiWeb 7.07.0.0 – 7.0.12
FortiWeb 7.27.2.0 – 7.2.12
FortiWeb 7.47.4.0 – 7.4.11
FortiWeb 7.67.6.0 – 7.6.6
FortiWeb 8.08.0.0 – 8.0.2

Fortinet advisory FG-IR-26-158 lists the patched builds. If immediate upgrade is not possible: restrict management interface access to trusted subnets and disable any internet-facing admin access — that buys time, it is not a fix.

The threat context: perimeter appliances are a reliable path from “advisory released” to “actively exploited.” FortiGate and FortiOS flaws have been weaponized by state-sponsored actors and ransomware crews within days of disclosure. A CVSS 9.8 auth bypass on an internet-facing security device is a first-tier patch priority regardless of exploitation status.

FortiManager — CVE-2026-70468, CVSS 8.1

CVE-2026-70468, CVSS 8.1, high. Authentication bypass via alternate path or channel (CWE-288). Affects on-premises FortiManager and FortiManager Cloud:

VariantAffected range
FortiManager7.2.5 – 7.2.9
FortiManager7.4.3 – 7.4.5
FortiManager7.6.1
FortiManager Cloud7.2.5 – 7.2.9
FortiManager Cloud7.4.3 – 7.4.5
FortiManager Cloud7.6.1

Advisory: FG-IR-26-160. Exploitation: unconfirmed.

FortiManager is the central management plane for FortiGate deployments — the system that holds configs, credentials, and policy for every managed device in an environment. A prior FortiManager zero-day, CVE-2024-47575, was mass-exploited by nation-state actors before most defenders had a patch window. The risk profile for management-plane auth bypasses is categorically worse than the CVSS score alone suggests.

Lower-priority advisories in the same batch

  • CVE-2026-71407 (FortiOS 7.6.1–7.6.6, CVSS 5.6, medium): Stack buffer overflow in the WAD daemon via crafted sockets. Exploitable only when explicit proxy with Kerberos authentication and SOCKS is enabled. Unauthenticated path.
  • CVE-2026-71408 (FortiOS 7.2–7.6 across multiple branches, CVSS 5.3, medium): Resource exhaustion leading to denial of service.

Patch these on your normal cycle unless the condition for CVE-2026-71407 matches your deployment (explicit proxy + Kerberos + SOCKS — if so, elevate it).

What to do

  1. FortiWeb — Identify deployed versions. Upgrade per FG-IR-26-158. No upgrade window yet: firewall management access to known-good subnets, disable internet-facing admin paths.
  2. FortiManager — Upgrade per FG-IR-26-160. Management interfaces should not be internet-accessible regardless of patch status — if they are, fix that now independent of the patch.
  3. FortiOS (medium-severity) — Patch on your standard cycle per the linked advisories.

Related: August was a heavy patch month across the board — see the August 2026 Patch Tuesday roundup and Cisco ASA/FTD CVE-2026-20349 KEV addition for perimeter device context.

Related CVEs
  • [ CRITICAL ] CVE-2026-26035 FortiWeb Authentication Bypass Allows Unauthenticated Login
  • [ HIGH ] CVE-2026-70468 FortiManager Authentication Bypass via Alternate Path

Found this useful? Share it.