H-ISAC TLP White: Fortinet Patches High-Severity Flaws in Various Products
H-ISAC TLP Green: Fortinet Patches High-Severity Flaws in Various Products (CVE-2026-26035 CVE-2026-70468 CVE-2026-70465, CVE-2026-49975)
Fortinet has released security advisories patching multiple vulnerabilities across its product suite, including high-severity authentication flaws in FortiWeb, FortiManager, and FortiClient for Windows.
Additional Info
Analysis
The most notable flaw, CVE-2026-26035, is an improper authentication vulnerability in FortiWeb that allows remote, unauthenticated attackers to log in to the GUI or CLI with arbitrary credentials when non-default wildcard administrator account configurations are enabled.
Additionally, Fortinet addressed CVE-2026-70468, an authentication-bypass flaw in FortiManager that allows remote attackers with a valid certificate to impersonate any managed FortiGate unit under specific CLI settings, as well as CVE-2026-70465, a high-severity buffer overflow in FortiClient for Windows that allows unauthenticated attackers who can tamper with DNS responses to execute arbitrary code.
The release also fixes lower-severity bugs in FortiWeb WAF, FortiOS, and FortiSIEM, and issues guidance on the CVE-2026-49975 HTTP/2 Bomb vulnerability affecting Apache HTTP Server.
Fortinet reports no evidence of active in-the-wild exploitation at the time of disclosure.
Recommendations
- Immediately update FortiWeb to versions 8.0.3, 7.6.7, 7.4.12, or 7.2.13 (or later) to resolve CVE-2026-26035.
- If you cannot immediately patch FortiWeb, disable the wildcard option for administrator accounts (Admin User Group) to neutralize the primary attack vector.
- Apply the latest software updates to FortiManager instances to patch the CVE-2026-70468 device impersonation vulnerability.
- Upgrade FortiClient Windows agents to non-vulnerable releases to protect against DNS-based buffer overflow and remote code execution attacks (CVE-2026-70465).
- Restrict administrative access to FortiWeb, FortiManager, and FortiOS consoles so they are accessible only via trusted internal management subnets or secure VPNs.
- Review the Health Industry Cybersecurity Practices (HICP): Managing Threats and Protecting Patients resources.
View the detailed report below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact: