Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
Fortinet released patches for eight vulnerabilities across FortiWeb, FortiManager, FortiClient for Windows, FortiOS, and FortiSIEM, including high-severity authentication flaws. The company also published guidance on CVE-2026-49975, the HTTP/2 Bomb attack affecting Apache HTTP Server, and noted no signs of active exploitation. #FortiWeb #FortiManager #FortiClient #FortiOS #FortiSIEM #ApacheHTTPServer #CVE-2026-26035 #CVE-2026-70468 #CVE-2026-70465 #CVE-2026-49975

Keypoints

  • Fortinet patched eight vulnerabilities across several of its products.
  • CVE-2026-26035 in FortiWeb could let attackers log in with a random username and password.
  • CVE-2026-70468 in FortiManager could allow impersonation of any managed FortiGate device.
  • CVE-2026-70465 in FortiClient for Windows could enable code execution through crafted DNS responses.
  • Fortinet also addressed issues in FortiWeb WAF, FortiOS, and FortiSIEM, and reported no known in-the-wild exploitation.

Read More: https://www.securityweek.com/fortinet-patches-authentication-flaws-in-fortiweb-and-fortimanager/