Articles

Fortinet FortiWeb Flaw CVE-2026-26035: Patch Now

A CVSS 9.8 authentication bug lets attackers log in to Fortinet FortiWeb with random credentials. It's part of a batch of Fortinet auth fixes. What to do.

Chisato Chisato · · 5 min read
Metal padlocks clipped onto a network cable, representing security controls on network hardware

Fortinet has patched a critical authentication flaw in its FortiWeb web application firewall that lets a remote, unauthenticated attacker log in to the appliance’s management interface using arbitrary credentials. Tracked as CVE-2026-26035 and disclosed on August 12, 2026 in advisory FG-IR-26-158, the bug is one of several authentication weaknesses Fortinet fixed across its product line this week — a batch that also touches FortiManager and FortiClient. For organizations running affected FortiWeb builds, this is a patch-now situation.

What the FortiWeb flaw is

CVE-2026-26035 is an improper authentication vulnerability — classified under CWE-287 and titled by Fortinet as “broken access control in the RADIUS type admin group.” The condition is specific: it applies when a FortiWeb device is configured to use remote RADIUS-type administrator authentication with the wildcard option enabled.

When that configuration is in place, the flaw lets a remote, unauthenticated attacker log in to the FortiWeb GUI or CLI using random usernames and passwords — effectively walking through the front door of the appliance’s management console without valid credentials. Because FortiWeb sits in front of web applications to inspect and filter traffic, control of its management plane is a serious foothold: an attacker who can administer the device can alter security policy, expose the traffic it protects, or use it as a pivot deeper into the network.

There is an important mitigating detail. The wildcard option is disabled by default, so environments that never enabled it are not exposed by default. That narrows the blast radius, but administrators cannot assume they are safe without checking their configuration — the wildcard setting is a legitimate feature that some deployments turn on deliberately.

How severe is it

Severity depends on who is scoring it. Fortinet rates the flaw High in its own advisory. Third-party vulnerability trackers assign a CVSS v3.1 base score of 9.8 — Critical — reflecting that the vulnerability is remotely exploitable, requires no authentication, and can hand over administrative access.

The gap between “High” (vendor) and “Critical” (trackers) is a common source of confusion. The practical read is straightforward: an unauthenticated, network-reachable path to admin login on a security appliance should be treated as critical for exposed devices, regardless of the label. Fortinet says there is no evidence of active exploitation in the wild as of disclosure — but Fortinet edge devices have a long history of being reverse-engineered from patches and attacked quickly, so the absence of exploitation today is not a reason to wait.

The fix and the workaround

Fortinet has released fixed builds. The patched FortiWeb versions are:

  • 8.0.3
  • 7.6.7
  • 7.4.12
  • 7.2.13

Upgrading to one of these releases (or later) is the primary remediation. For organizations that cannot patch immediately, Fortinet’s recommended workaround is to disable the wildcard setting for RADIUS-type administrator accounts, which removes the precondition the exploit relies on.

The rest of the batch: FortiManager and FortiClient

CVE-2026-26035 did not ship alone. Health-sector threat-sharing group H-ISAC flagged on August 13 that Fortinet patched high-severity flaws across several products, and two others stand out.

FortiManager — CVE-2026-70468. This is an authentication bypass that allows a remote attacker to impersonate any FortiGate device managed by FortiManager, carrying a CVSS score of 7.3. Exploitation is not trivial: it requires a specific CLI command to be enabled and the attacker to present a valid certificate. But because FortiManager is the central console many organizations use to push policy to fleets of firewalls, an attacker who can masquerade as a managed device could feed false state or interfere with fleet management at scale.

FortiClient for Windows — CVE-2026-70465. A separate buffer overflow in the Windows endpoint agent could let an unauthenticated attacker who can intercept or manipulate DNS responses execute arbitrary code on the affected system. That raises the stakes beyond network appliances to the endpoints themselves, and it rewards attackers already positioned on a network path — for example, on a compromised local network or a hostile Wi-Fi segment.

Taken together, the three flaws span the web application firewall, the management console, and the endpoint client — three different layers of a Fortinet deployment, all patched in the same window.

Why edge and security appliances keep landing on this list

Network security devices have become one of the most contested categories in enterprise security, precisely because they sit at the boundary and are trusted with broad access. The past several weeks alone have brought a Cisco Secure Firewall Management Center zero-day, an Arista VeloCloud zero-day, and a VMware vCenter flaw exploited within days of disclosure. The common thread is that these systems are internet-facing by design, run on long patch cycles, and — when compromised — offer attackers exactly the kind of privileged position they want.

A web application firewall like FortiWeb is a defensive control, which is what makes an authentication bypass on it particularly awkward: the device meant to filter malicious traffic becomes the target. Attackers increasingly treat the security stack itself as the softest way in.

What it means

For anyone running FortiWeb, the immediate action is simple and time-sensitive: inventory your FortiWeb devices, check whether RADIUS-type admin authentication with the wildcard option is enabled, and patch to 8.0.3, 7.6.7, 7.4.12, or 7.2.13. If you cannot patch right away, disable the wildcard setting as an interim measure. The default-disabled configuration limits who is exposed, but “probably not affected” is not a posture to hold on a CVSS 9.8 admin-login bypass — verify it.

The broader lesson is about exposure management on the security stack. Every organization running FortiManager and FortiClient alongside FortiWeb just got three separate reasons to check versions in the same week. Treat the whole Fortinet estate as one patch campaign rather than three tickets: confirm the FortiManager fix for CVE-2026-70468 and the FortiClient fix for CVE-2026-70465 at the same time you handle FortiWeb.

What to watch next is exploitation. Fortinet reports no in-the-wild activity yet, but the pattern for its edge products is that proof-of-concept code and scanning tend to follow disclosure quickly. The most useful early-warning signals will be a CISA Known Exploited Vulnerabilities listing for any of these CVEs and any uptick in scanning for exposed FortiWeb management interfaces — either of which would turn a “patch soon” into a “patch tonight.”

Chisato Chisato · · 6 min read

LiteLLM CVE-2026-59822: CISA KEV AI Infra Attacks

CISA added seven exploited flaws to its KEV catalog on Sept. 2, and three target AI infrastructure — LiteLLM, Kestra, and Starlette. What to patch and why it matters.

#Security #Vulnerability #AI
Chisato Chisato · · 6 min read

Cisco Nexus 9000 CVE-2026-20212: Root RCE Flaw

Cisco patched CVE-2026-20212, a CVSS 9.8 flaw letting unauthenticated attackers run code as root on Nexus 9000 switches. Affected models, ports, and fixes.

#Security #Vulnerability #Cisco