Fortinet has released crucial updates to address several authentication vulnerabilities identified in its FortiWeb, FortiManager, and FortiClient products. These updates are critical given the potential security risks associated with the affected systems, and Fortinet urges administrators to apply these patches promptly.
FortiWeb Vulnerability Overview
The most significant flaw, designated as CVE-2026-26035, affects FortiWeb’s login process. This vulnerability, with a CVSS score ranging from 8.8 to 9.8, is particularly dangerous as it could be easily exploited if systems are not correctly configured. According to Fortinet, the issue arises with the improper authentication setup when a FortiWeb administrator account uses Remote RADIUS Type authentication with the “wildcard” setting enabled.
This misconfiguration allows unauthorized users to log into the FortiWeb interface using arbitrary credentials. The vulnerability affects multiple FortiWeb versions, including 8.0.0 through 8.0.2, and other earlier iterations. Fortinet has provided fixes in subsequent versions, specifically in FortiWeb 8.0.3 and others. For those using legacy versions, Fortinet advises consulting their support channels for further assistance.
FortiManager and FortiClient Concerns
Another critical vulnerability, CVE-2026-70468, was identified in FortiManager, a platform critical for managing FortiGate firewalls. This flaw, which has a CVSS score of 8.1, is a result of an authentication bypass vulnerability within the FGFM protocol. Exploitation of this flaw could allow attackers to impersonate FortiGate devices, potentially altering firewall policies.
FortiManager versions 7.6.1, 7.4.3 through 7.4.5, and 7.2.5 through 7.2.9 are affected, with patches available in their respective newer releases. Additionally, FortiClient for Windows has a buffer overflow vulnerability, CVE-2026-70465, which could allow attackers to execute arbitrary code by intercepting DNS responses.
Security Implications and Recommendations
Fortinet’s products are often targets for cyber threats, making these updates particularly pressing. Administrators are advised to treat these updates as high-priority to prevent potential exploits. Fortinet has not yet observed any active attacks exploiting these vulnerabilities, but given the low complexity required to exploit them, the situation could change rapidly.
In instances where immediate patching is not possible, Fortinet recommends disabling specific settings, such as the wildcard setting on Remote Type administrator accounts, to mitigate risks. Security teams should remain vigilant and ensure that all systems are updated to the latest secure versions.
As Fortinet continues to enhance its security posture, these updates reinforce the importance of maintaining up-to-date systems to protect against emerging threats.
