Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Addresses Critical Authentication Vulnerabilities

Fortinet Addresses Critical Authentication Vulnerabilities

Posted on August 13, 2026 By CWS

Fortinet has released essential updates to mitigate eight vulnerabilities discovered across several of its products. Among these, two significant authentication flaws were identified in FortiWeb and FortiManager, posing high-severity risks.

FortiWeb Authentication Issue

A critical issue in FortiWeb involved improper authentication due to specific non-default configurations. This flaw, designated as CVE-2026-26035, could potentially allow unauthorized remote access to the FortiWeb interface using arbitrary credentials.

The vulnerability is linked to the wildcard setting for admin accounts, which by default is deactivated. If activated, it enables any username on a remote server to be matched with a Remote User account. FortiWeb versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13 now include patches for this vulnerability. Fortinet advises users to disable the wildcard setting as a precaution.

FortiManager Flaw and Other Vulnerabilities

Another vulnerability, CVE-2026-70468, was found in FortiManager, allowing attackers to impersonate any FortiGate device managed by it. This bypass requires specific command-line interface options and a valid certificate for exploitation.

In addition to these, Fortinet addressed a high-severity buffer overflow vulnerability (CVE-2026-70465) in FortiClient for Windows. This flaw could enable unauthorized code execution through manipulated DNS responses.

Additional Security Patches

Beyond the major issues, Fortinet also patched medium- and low-severity vulnerabilities in FortiWeb WAF, FortiOS, and FortiSIEM. The company issued an advisory detailing the impact of CVE-2026-49975, related to the HTTP/2 Bomb attack affecting Apache HTTP Server.

Currently, Fortinet reports no known incidents of these vulnerabilities being exploited in real-world scenarios. Users are advised to review the company’s PSIRT advisories for more comprehensive information.

Keeping systems updated with the latest patches is crucial for maintaining robust cybersecurity defenses. Fortinet’s proactive measures underscore the importance of addressing vulnerabilities promptly to safeguard network infrastructures.

Security Week News Tags:authentication flaws, buffer overflow, CVE-2026-26035, CVE-2026-70468, Cybersecurity, FortiManager, Fortinet, FortiWeb, IT security, network security, PSIRT advisories, security updates, software vulnerabilities, vulnerability patches

Post navigation

Previous Post: Trump Memo Allows Private Firms in Cyber Operations
Next Post: Kimwolf Botnet Exploits Chrome Fingerprints in DDoS Attacks

Related Posts

Unpatched Tenda Firmware Backdoor Risks Device Security Unpatched Tenda Firmware Backdoor Risks Device Security Security Week News
AegisAI Secures M to Enhance AI Email Protection AegisAI Secures $36M to Enhance AI Email Protection Security Week News
Identity Security Firm Saviynt Raises 0 Million at  Billion Valuation  Identity Security Firm Saviynt Raises $700 Million at $3 Billion Valuation  Security Week News
Suspected DoppelPaymer Ransomware Group Member Arrested Suspected DoppelPaymer Ransomware Group Member Arrested Security Week News
Cisco Introduces Cost-Effective AI for Code Security Cisco Introduces Cost-Effective AI for Code Security Security Week News
Adobe Patches Critical Code Execution Bugs Adobe Patches Critical Code Execution Bugs Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • LiteLLM Breach Exposes Cloud Keys in 2,488 Companies
  • Team8 Raises $365M to Boost Enterprise Tech Ventures
  • Kimwolf Botnet Exploits Chrome Fingerprints in DDoS Attacks
  • Fortinet Addresses Critical Authentication Vulnerabilities
  • Trump Memo Allows Private Firms in Cyber Operations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • LiteLLM Breach Exposes Cloud Keys in 2,488 Companies
  • Team8 Raises $365M to Boost Enterprise Tech Ventures
  • Kimwolf Botnet Exploits Chrome Fingerprints in DDoS Attacks
  • Fortinet Addresses Critical Authentication Vulnerabilities
  • Trump Memo Allows Private Firms in Cyber Operations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark