Critical Vulnerabilities in Fortinet Products Allow Unauthorized Access

Critical Vulnerabilities in Fortinet Products Allow Unauthorized Access

First seen 14 Aug 2026, 13:29 UTC Heise.Dewww.fortiguard.com 89% similarity 72.0

Article Content

Browse articles
ThreatCluster

Fortinet has disclosed multiple vulnerabilities affecting its products, including FortiWeb, FortiManager, and FortiClientWindows. The most critical, CVE-2026-26035, allows remote unauthenticated access to FortiWeb instances if the wildcard option is enabled. Other vulnerabilities, CVE-2026-70468 and CVE-2026-70465, also pose significant risks, permitting unauthorized access under specific conditions. Patches have been released for affected versions, including 7.2.13, 7.4.12, 7.6.7, and 8.0.3 for FortiWeb. Administrators are advised to apply these patches promptly, as these products are often central to corporate networks. The vulnerabilities were published on August 12, 2026, and there are currently no reports of active exploitation. However, the potential for serious breaches remains high, prompting urgent action from security teams.

Key Points: • CVE-2026-26035 allows remote unauthenticated access to FortiWeb if wildcard option is enabled. • Patches for critical vulnerabilities have been released for multiple Fortinet products. • Administrators are urged to apply patches immediately to mitigate risks of unauthorized access.

ThreatCluster AI How this analysis works

Timeline

2026-08-12
Multiple CVEs published
Fortinet disclosed CVEs 2026-26035, 2026-70468, and 2026-70465, detailing severe vulnerabilities in FortiWeb, FortiManager, and FortiClientWindows.
www.fortiguard.com
2026-08-12
CVE-2026-26035 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-12
CVE-2026-70465 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-12
CVE-2026-70468 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-14
Patches released
Fortinet released patches for affected versions of FortiWeb, FortiManager, and FortiClientWindows to address the vulnerabilities.
Heise.De
Recent
CISA warns of potential attacks
The US IT security authority CISA issued a warning about potential attacks targeting FortiOS, highlighting the urgency of patching.
Heise.De

Community

Browse all →

Tracked Entities in This Story