A critical vulnerability in Fortinet's FortiWeb application allows attackers to log in using arbitrary credentials, potentially granting them administrative access to affected systems. The flaw, identified with the identifier CVE-2026-26035 and rated as high severity, enables remote exploitation without authentication. This issue affects specific versions of FortiWeb, including 7.2.13, 7.4.12, 7.6.7, and 8.0.3, which have since been patched by the vendor. However, the vulnerability can only be exploited if the Wildcard option is enabled in the Remote-Type Administrator Account settings, a configuration that is not active by default. The exploit works by allowing unauthorized users to bypass login mechanisms entirely, effectively granting them access to system resources as administrators. According to security researchers, this could lead to severe consequences, such as data breaches, system manipulation, or disruption of network services. Fortinet has released updated versions of its software to address these issues, urging customers to apply the patches promptly to mitigate risks. In addition to the FortiWeb vulnerability, two other high-severity flaws were disclosed. One of these, CVE-2026-70468, impacts FortiManager and FortiManager Cloud. It allows attackers to bypass authentication and gain unauthorized access to systems, provided they possess a valid certificate. FortiManager version 8.0 is unaffected by this vulnerability, while earlier versions require updates to versions 7.2.10, 7.4.6, and 7.6.2 to resolve the issue. Another high-risk vulnerability, CVE-2026-70465, affects FortiClientWindows. If an attacker is able to manipulate DNS responses, malicious code can be delivered to vulnerable systems. However, FortiClientWindows version 8.0 is not impacted, nor are versions 7.2.12 and 7.4.4, which have already received necessary fixes. Beyond these high-severity vulnerabilities, several medium- and low-severity issues were also identified. These include potential avenues for denial-of-service (DoS) attacks, although there have been no confirmed reports of ongoing exploitation so far. Despite this, cybersecurity experts emphasize the importance of applying available patches immediately. Many Fortinet products operate within central areas of corporate networks, making them attractive targets for cybercriminals seeking to disrupt operations or extract sensitive information. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) had previously issued warnings in late July regarding attacks targeting FortiOS, another product line from Fortinet. These alerts highlight the growing concern over the security of enterprise-grade networking equipment and the need for continuous monitoring and proactive defense measures. Security professionals recommend that organizations conduct thorough audits of their network infrastructure to identify any unpatched devices running vulnerable versions of Fortinet’s software. They also advise implementing additional layers of security, such as multi-factor authentication and regular penetration testing, to reduce the risk of successful exploitation. While Fortinet has taken steps to address the vulnerabilities through timely patch releases, the broader implications of these findings underscore the persistent challenges faced by IT departments in maintaining secure environments. As new threats continue to emerge, the responsibility falls on both vendors and users to remain vigilant and ensure that all systems are kept up-to-date with the latest security enhancements. Organizations using Fortinet products should review their current configurations and update affected components as soon as possible. Failure to act could expose critical assets to potential compromise, especially given the strategic role these devices often play in securing internal communications and external connections.
★
Keep the news honest.
ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.
Become a Supporter