Skip to content
Fortinet FortiWeb: Attackers can log in with any credentials

Fortinet FortiWeb: Attackers can log in with any credentials

Heise.De • August 14, 2026

FortiClientWindows, FortiManager, FortiOS, FortiPAM and FortiWeb are vulnerable. In the worst case, attackers can access systems as admin. Patches resolve the security issues.

A vulnerability ( CVE-2026-26035 “ high ”) in FortiWeb is considered the most dangerous. It allows attackers to remotely access instances without authentication using any credentials. However, this only works if the wildcard option is set in the options for the remote type administrator account. This is not the case by default. Versions 7.2.13, 7.4.12, 7.6.7 and 8.0.3 have been fixed.

Another vulnerability ( CVE-2026-70468 ) with a threat level of “ high ” affects FortiManager and FortiManager Cloud. Forti Manager 8.0 is not affected. Here too, attackers can bypass login and gain unauthorized access to systems. However, they must have a valid certificate. Releases 7.2.10, 7.4.6 and 7.6.2 provide a remedy.

The third vulnerability classified as “ high ” ( CVE-2026-70465 ) affects FortiClientWindows. If an attacker is in a position to manipulate DNS responses, malicious code can reach systems. FortiClientWindows 8.0 is not vulnerable. 7.2.12 and 7.4.4 are protected against it.

The remaining vulnerabilities are rated with threat levels “ medium ” and “ low ”. These can lead to DoS attacks, among other things. Even though there are no reports of ongoing attacks so far, administrators should not postpone patching. After all, Fortinet products often operate in central network areas of companies and are therefore lucrative targets.

Most recently, the US IT security authority CISA warned at the end of July attacks on FortiOS.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities