Fortinet released patches for eight vulnerabilities across FortiWeb, FortiManager, FortiClient for Windows, FortiOS, and FortiSIEM, including high-severity authentication flaws. The company also published guidance on CVE-2026-49975, the HTTP/2 Bomb attack affecting Apache HTTP Server, and noted no signs of active exploitation. #FortiWeb #FortiManager #FortiClient #FortiOS #FortiSIEM #ApacheHTTPServer #CVE-2026-26035 #CVE-2026-70468 #CVE-2026-70465 #CVE-2026-49975
Keypoints
- Fortinet patched eight vulnerabilities across several of its products.
- CVE-2026-26035 in FortiWeb could let attackers log in with a random username and password.
- CVE-2026-70468 in FortiManager could allow impersonation of any managed FortiGate device.
- CVE-2026-70465 in FortiClient for Windows could enable code execution through crafted DNS responses.
- Fortinet also addressed issues in FortiWeb WAF, FortiOS, and FortiSIEM, and reported no known in-the-wild exploitation.
Read More: https://www.securityweek.com/fortinet-patches-authentication-flaws-in-fortiweb-and-fortimanager/