Cybersecurity & Protection

Fortinet Closes Flaws in FortiWeb, FortiManager, and FortiClient

Aug 14, 2026 2 min read
All articles

Fortinet has closed several security vulnerabilities in FortiClientWindows, FortiManager, FortiOS, FortiPAM, and FortiWeb. In the worst case, attackers could gain administrator access to affected systems. Matching patches are available and should be applied promptly, since Fortinet products often sit in central areas of corporate networks, making them worthwhile targets.

The three most important flaws

The most dangerous is a high-severity vulnerability (CVE-2026-26035) in FortiWeb. It lets attackers access instances remotely and without authentication using arbitrary credentials. That only works, though, if the wildcard option is enabled for the remote-type administrator account, which isn't the case by default. Versions 7.2.13, 7.4.12, 7.6.7, and 8.0.3 fix the issue.

Another high-severity flaw (CVE-2026-70468) affects FortiManager and FortiManager Cloud; FortiManager 8.0 is not affected. Here too, attackers can bypass authentication and gain unauthorized access, but they need a valid certificate to do so. Versions 7.2.10, 7.4.6, and 7.6.2 provide the fix.

The third high-severity vulnerability (CVE-2026-70465) affects FortiClientWindows. If an attacker is positioned to manipulate DNS responses, they can get malicious code onto affected systems. FortiClientWindows 8.0 isn't vulnerable, while versions 7.2.12 and 7.4.4 are protected.

Remaining risks and recommendation

The rest of the fixed vulnerabilities are rated medium and low severity and enable, among other things, denial-of-service attacks. So far there are no reports of ongoing attacks against these flaws, but admins shouldn't put off patching. Just at the end of July, the US security agency CISA warned about attacks on FortiOS.