Skip to content
feed: live
>_ 0dayNews
CVE Record
[ HIGH ] CVE-2026-70468

FortiManager Authentication Bypass via Alternate Path

Authentication bypass in FortiManager 7.2.5 through 7.6.1 (and cloud variants) allows unauthorized access to the central management plane. CVSS 8.1, patch available.

cat cve-2026-70468.json
Vendor
Fortinet
Product
FortiManager
CVSS
8.1
EPSS (exploit probability)
N/A
Status
patched
Published

Authentication bypass using an alternate path or channel (CWE-288) in Fortinet FortiManager, affecting both on-premises and cloud deployments. An attacker who exploits this flaw gains unauthorized access to the FortiManager management plane — the central configuration controller for FortiGate networks.

Affected versions

VariantAffected range
FortiManager7.2.5 – 7.2.9
FortiManager7.4.3 – 7.4.5
FortiManager7.6.1
FortiManager Cloud7.2.5 – 7.2.9
FortiManager Cloud7.4.3 – 7.4.5
FortiManager Cloud7.6.1

Patch and mitigation

Apply patched builds per Fortinet advisory FG-IR-26-160. FortiManager management interfaces should not be internet-accessible under any circumstances — verify network segmentation alongside patching.

Exploitation status: unconfirmed in the wild as of initial publication.