H-ISAC TLP White: Fortinet Patches High-Severity Flaws in Various Products

H-ISAC TLP Green: Fortinet Patches High-Severity Flaws in Various Products (CVE-2026-26035 CVE-2026-70468 CVE-2026-70465, CVE-2026-49975)

Fortinet has released security advisories patching multiple vulnerabilities across its product suite, including high-severity authentication flaws in FortiWeb, FortiManager, and FortiClient for Windows.

Additional Info

Analysis

The most notable flaw, CVE-2026-26035, is an improper authentication vulnerability in FortiWeb that allows remote, unauthenticated attackers to log in to the GUI or CLI with arbitrary credentials when non-default wildcard administrator account configurations are enabled.

Additionally, Fortinet addressed CVE-2026-70468, an authentication-bypass flaw in FortiManager that allows remote attackers with a valid certificate to impersonate any managed FortiGate unit under specific CLI settings, as well as CVE-2026-70465, a high-severity buffer overflow in FortiClient for Windows that allows unauthenticated attackers who can tamper with DNS responses to execute arbitrary code.

The release also fixes lower-severity bugs in FortiWeb WAF, FortiOS, and FortiSIEM, and issues guidance on the CVE-2026-49975 HTTP/2 Bomb vulnerability affecting Apache HTTP Server.

Fortinet reports no evidence of active in-the-wild exploitation at the time of disclosure.

Recommendations

  • Immediately update FortiWeb to versions 8.0.3, 7.6.7, 7.4.12, or 7.2.13 (or later) to resolve CVE-2026-26035.
  • If you cannot immediately patch FortiWeb, disable the wildcard option for administrator accounts (Admin User Group) to neutralize the primary attack vector.
  • Apply the latest software updates to FortiManager instances to patch the CVE-2026-70468 device impersonation vulnerability.
  • Upgrade FortiClient Windows agents to non-vulnerable releases to protect against DNS-based buffer overflow and remote code execution attacks (CVE-2026-70465).
  • Restrict administrative access to FortiWeb, FortiManager, and FortiOS consoles so they are accessible only via trusted internal management subnets or secure VPNs.
  • Review the Health Industry Cybersecurity Practices (HICP): Managing Threats and Protecting Patients resources.

View the detailed report below.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272