Skip to content
Critical Vulnerabilities in Fortinet Products Allow Unauthorized Access

Critical Vulnerabilities in Fortinet Products Allow Unauthorized Access

First seen 14 Aug 2026, 13:29 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 15, 2026 at 12:07 UTC
  • •CVE-2026-26035 allows remote unauthenticated access to FortiWeb if wildcard option is enabled.
  • •Patches for critical vulnerabilities have been released for multiple Fortinet products.
  • •Administrators are urged to apply patches immediately to mitigate risks of unauthorized access.

Fortinet has disclosed multiple vulnerabilities affecting its products, including FortiWeb, FortiManager, and FortiClientWindows. The most critical, CVE-2026-26035, allows remote unauthenticated access to FortiWeb instances if the wildcard option is enabled. Other vulnerabilities, CVE-2026-70468 and CVE-2026-70465, also pose significant risks, permitting unauthorized access under specific conditions. Patches have been released for affected versions, including 7.2.13, 7.4.12, 7.6.7, and 8.0.3 for FortiWeb. Administrators are advised to apply these patches promptly, as these products are often central to corporate networks. The vulnerabilities were published on August 12, 2026, and there are currently no reports of active exploitation. However, the potential for serious breaches remains high, prompting urgent action from security teams.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 54d ago How this analysis works

Timeline

2026-08-12
Multiple CVEs published
Fortinet disclosed CVEs 2026-26035, 2026-70468, and 2026-70465, detailing severe vulnerabilities in FortiWeb, FortiManager, and FortiClientWindows.
www.fortiguard.com
2026-08-12
CVE-2026-26035 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-12
CVE-2026-70465 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-12
CVE-2026-70468 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-14
Patches released
Fortinet released patches for affected versions of FortiWeb, FortiManager, and FortiClientWindows to address the vulnerabilities.
Heise.De
Recent
CISA warns of potential attacks
The US IT security authority CISA issued a warning about potential attacks targeting FortiOS, highlighting the urgency of patching.
Heise.De

More articles in this cluster (4)

Following this threat?

Track Fortinet and CVE-2026-26035 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed