Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Addresses Critical Security Flaws in Key Products

Fortinet Addresses Critical Security Flaws in Key Products

Posted on August 13, 2026 By CWS

Fortinet has released crucial updates to address several authentication vulnerabilities identified in its FortiWeb, FortiManager, and FortiClient products. These updates are critical given the potential security risks associated with the affected systems, and Fortinet urges administrators to apply these patches promptly.

FortiWeb Vulnerability Overview

The most significant flaw, designated as CVE-2026-26035, affects FortiWeb’s login process. This vulnerability, with a CVSS score ranging from 8.8 to 9.8, is particularly dangerous as it could be easily exploited if systems are not correctly configured. According to Fortinet, the issue arises with the improper authentication setup when a FortiWeb administrator account uses Remote RADIUS Type authentication with the “wildcard” setting enabled.

This misconfiguration allows unauthorized users to log into the FortiWeb interface using arbitrary credentials. The vulnerability affects multiple FortiWeb versions, including 8.0.0 through 8.0.2, and other earlier iterations. Fortinet has provided fixes in subsequent versions, specifically in FortiWeb 8.0.3 and others. For those using legacy versions, Fortinet advises consulting their support channels for further assistance.

FortiManager and FortiClient Concerns

Another critical vulnerability, CVE-2026-70468, was identified in FortiManager, a platform critical for managing FortiGate firewalls. This flaw, which has a CVSS score of 8.1, is a result of an authentication bypass vulnerability within the FGFM protocol. Exploitation of this flaw could allow attackers to impersonate FortiGate devices, potentially altering firewall policies.

FortiManager versions 7.6.1, 7.4.3 through 7.4.5, and 7.2.5 through 7.2.9 are affected, with patches available in their respective newer releases. Additionally, FortiClient for Windows has a buffer overflow vulnerability, CVE-2026-70465, which could allow attackers to execute arbitrary code by intercepting DNS responses.

Security Implications and Recommendations

Fortinet’s products are often targets for cyber threats, making these updates particularly pressing. Administrators are advised to treat these updates as high-priority to prevent potential exploits. Fortinet has not yet observed any active attacks exploiting these vulnerabilities, but given the low complexity required to exploit them, the situation could change rapidly.

In instances where immediate patching is not possible, Fortinet recommends disabling specific settings, such as the wildcard setting on Remote Type administrator accounts, to mitigate risks. Security teams should remain vigilant and ensure that all systems are updated to the latest secure versions.

As Fortinet continues to enhance its security posture, these updates reinforce the importance of maintaining up-to-date systems to protect against emerging threats.

Cyber Security News Tags:Authentication, CVE, Cybersecurity, FortiClient, FortiManager, Fortinet, FortiWeb, Patch, Security, software update, Vulnerabilities

Post navigation

Previous Post: Armored Likho Tool Compromises Telegram & Records Conversations

Related Posts

Zscaler Acquires Enterprise AI Security Firm SPLX to Boost Zero Trust Exchange Zscaler Acquires Enterprise AI Security Firm SPLX to Boost Zero Trust Exchange Cyber Security News
GitLab Security Alert: Critical XSS and DoS Flaws Fixed GitLab Security Alert: Critical XSS and DoS Flaws Fixed Cyber Security News
Microsoft to Launch New Secure Default Settings for Exchange and Teams APIs Microsoft to Launch New Secure Default Settings for Exchange and Teams APIs Cyber Security News
PhantomRaven Attack Involves 126 Malicious npm Packages with Over 86,000 Downloads Hiding Malicious Code PhantomRaven Attack Involves 126 Malicious npm Packages with Over 86,000 Downloads Hiding Malicious Code Cyber Security News
Microsoft Investigating Issue Impacting Exchange Online, Teams, and M365 Suite Microsoft Investigating Issue Impacting Exchange Online, Teams, and M365 Suite Cyber Security News
Cybercriminals Exploit PowerShell for Sophisticated Phishing Attacks Cybercriminals Exploit PowerShell for Sophisticated Phishing Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fortinet Addresses Critical Security Flaws in Key Products
  • Armored Likho Tool Compromises Telegram & Records Conversations
  • Jewelbug Exploits Browsers to Infiltrate Government Systems
  • North Korean IT Workers Exploit AI and Remote Access
  • Data Breach at ShipMonk Risks Trezor Customer Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fortinet Addresses Critical Security Flaws in Key Products
  • Armored Likho Tool Compromises Telegram & Records Conversations
  • Jewelbug Exploits Browsers to Infiltrate Government Systems
  • North Korean IT Workers Exploit AI and Remote Access
  • Data Breach at ShipMonk Risks Trezor Customer Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark