ON
← Back to feed
Fortinet FortiWeb: attackers can log in with any access data
Germany💻 Technology9 days ago

Fortinet FortiWeb: attackers can log in with any access data

Ein Sicherheitsupdate für Fortinet-Produkte hat drei schwere Schwachstellen identifiziert, die Angreifer nutzen könnten, um systematisch auf Systeme zuzugreifen. Die vulnerablen Produkte umfassen FortiWeb, FortiManager und FortiClientWindows. Eine besonders gefährliche Schwachstelle (CVE-2026-26035) ermöglicht einen Fernangriff ohne Authentifizierung, vorausgesetzt, die Wildcard-Option im Remote-Type-Administrator-Account ist aktiviert. Andere Schwachstellen erlauben unbefugten Zugriff, falls gültige Zertifikate vorliegen oder DNS-Manipulation möglich ist. Fortinet hat Patches bereitgestellt, die diese Probleme beheben. Obwohl bisher keine aktiven Angriffe gemeldet wurden, wird empfohlen, die Updates schnellstmöglich zu installieren, da die Produkte in zentralen Unternehmensnetzwerken eingesetzt werden.

A critical vulnerability in Fortinet's FortiWeb application allows attackers to log in using arbitrary credentials, potentially granting them administrative access to affected systems. The flaw, identified with the identifier CVE-2026-26035 and rated as high severity, enables remote exploitation without authentication. This issue affects specific versions of FortiWeb, including 7.2.13, 7.4.12, 7.6.7, and 8.0.3, which have since been patched by the vendor. However, the vulnerability can only be exploited if the Wildcard option is enabled in the Remote-Type Administrator Account settings, a configuration that is not active by default. The exploit works by allowing unauthorized users to bypass login mechanisms entirely, effectively granting them access to system resources as administrators. According to security researchers, this could lead to severe consequences, such as data breaches, system manipulation, or disruption of network services. Fortinet has released updated versions of its software to address these issues, urging customers to apply the patches promptly to mitigate risks. In addition to the FortiWeb vulnerability, two other high-severity flaws were disclosed. One of these, CVE-2026-70468, impacts FortiManager and FortiManager Cloud. It allows attackers to bypass authentication and gain unauthorized access to systems, provided they possess a valid certificate. FortiManager version 8.0 is unaffected by this vulnerability, while earlier versions require updates to versions 7.2.10, 7.4.6, and 7.6.2 to resolve the issue. Another high-risk vulnerability, CVE-2026-70465, affects FortiClientWindows. If an attacker is able to manipulate DNS responses, malicious code can be delivered to vulnerable systems. However, FortiClientWindows version 8.0 is not impacted, nor are versions 7.2.12 and 7.4.4, which have already received necessary fixes. Beyond these high-severity vulnerabilities, several medium- and low-severity issues were also identified. These include potential avenues for denial-of-service (DoS) attacks, although there have been no confirmed reports of ongoing exploitation so far. Despite this, cybersecurity experts emphasize the importance of applying available patches immediately. Many Fortinet products operate within central areas of corporate networks, making them attractive targets for cybercriminals seeking to disrupt operations or extract sensitive information. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) had previously issued warnings in late July regarding attacks targeting FortiOS, another product line from Fortinet. These alerts highlight the growing concern over the security of enterprise-grade networking equipment and the need for continuous monitoring and proactive defense measures. Security professionals recommend that organizations conduct thorough audits of their network infrastructure to identify any unpatched devices running vulnerable versions of Fortinet’s software. They also advise implementing additional layers of security, such as multi-factor authentication and regular penetration testing, to reduce the risk of successful exploitation. While Fortinet has taken steps to address the vulnerabilities through timely patch releases, the broader implications of these findings underscore the persistent challenges faced by IT departments in maintaining secure environments. As new threats continue to emerge, the responsibility falls on both vendors and users to remain vigilant and ensure that all systems are kept up-to-date with the latest security enhancements. Organizations using Fortinet products should review their current configurations and update affected components as soon as possible. Failure to act could expose critical assets to potential compromise, especially given the strategic role these devices often play in securing internal communications and external connections.

Go to the primary sources (3)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 85Objective 809 days ago
Fortinet FortiWeb: attackers can log in with any access data

Ein Sicherheitsupdate für Fortinet-Produkte hat drei schwere Schwachstellen identifiziert, die Angreifer nutzen könnten, um systematisch auf Systeme zuzugreifen. Die vulnerablen Produkte umfassen FortiWeb, FortiManager und FortiClientWindows. Eine besonders gefährliche Schwachstelle (CVE-2026-26035) ermöglicht einen Fernangriff ohne Authentifizierung, vorausgesetzt, die Wildcard-Option im Remote-Type-Administrator-Account ist aktiviert. Andere Schwachstellen erlauben unbefugten Zugriff, falls gültige Zertifikate vorliegen oder DNS-Manipulation möglich ist. Fortinet hat Patches bereitgestellt, die diese Probleme beheben. Obwohl bisher keine aktiven Angriffe gemeldet wurden, wird empfohlen, die Updates schnellstmöglich zu installieren, da die Produkte in zentralen Unternehmensnetzwerken eingesetzt werden.

Bias read (Center): Der Artikel beschäftigt sich rein technisch mit Sicherheitsupdates und Schwachstellen in Softwareprodukten. Es wird keine politische Haltung oder Meinung vertreten, sondern lediglich Fakten und Warnungen vor potenziellen Sicherheitsrisiken. Der Ton bleibt sachlich und informativ, ohne eine bestimmte

Why factuality (85): The article accurately reports the existence of the CVE-2026-26035 vulnerability in FortiWeb, including the affected versions and recommended patches. It aligns with the primary source document by mentioning the need to disable the Wildcard setting and provides correct version numbers for fixes. How

Why objectivity (80): The tone remains generally neutral, focusing on the security implications without overt bias. The article uses terms like 'Angreifer' (attackers) and 'unbefugt' (unauthorized) which are standard in security reporting. While it emphasizes the severity of the issue, it does not take sides or express p

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories