Critical Authentication Bypass in FortiWeb Headlines Four New Fortinet Vulnerability Disclosures
August 18th, 2026
Critical
.jpg)
Our Cyber Threat Intelligence Unit has identified four vulnerabilities affecting Fortinet's FortiWeb, FortiManager, FortiClient for Windows, and FortiPAM/FortiProxy/FortiSwitchManager product lines, publicly disclosed on August 12, 2026. The most severe is an improper authentication vulnerability in FortiWeb's Remote RADIUS Type Admin Authentication feature. It may allow a remote, unauthenticated attacker to log in to the FortiWeb GUI or CLI with arbitrary credentials when the non-default Wildcard setting is enabled on a Remote Type administrator account, granting full administrative control of the appliance. This issue is rated Critical (CVSS 9.8) in its NVD record, though FortiGuard's advisory rates it High (8.8). A second authentication bypass vulnerability affecting FortiManager and FortiManager Cloud allows an attacker with a valid certificate to impersonate any FortiGate device managed through the FGFM protocol, contingent on a specific CLI configuration option being set. A third, unrelated buffer overflow vulnerability in FortiClient for Windows may allow an unauthenticated attacker positioned to alter or spoof DNS responses to execute arbitrary code on the endpoint. A fourth, lower-severity denial-of-service vulnerability, stemming from a third-party Apache HTTP Server component and known as "HTTP/2 Bomb," affects FortiPAM, FortiProxy, and FortiSwitchManager, with several additional products still under vendor investigation. The FortiManager and FortiClient issues carry a vendor rating of High, and the HTTP/2 Bomb issue is rated Medium. The vendor has not observed active exploitation of any of the four in the wild as of publication. Organizations running affected FortiWeb, FortiManager, FortiClient for Windows, FortiPAM, FortiProxy, or FortiSwitchManager deployments should prioritize patching or apply the documented workarounds without delay.
Technical Details
Threat Type: Authentication Bypass / Memory Corruption / Denial of Service (Vulnerability Disclosure: no associated campaign or exploitation observed).
Severity: Critical.
CVE-2026-26035 – 9.8 (Critical, per NVD/CNA record; FortiGuard's own PSIRT advisory separately lists 8.8 High)
CVE-2026-70468 – 7.3 (High)
CVE-2026-70465 – 7.3 (High)
CVE-2026-49975 – 5.8 (Medium)
CVE-2026-26035 — FortiWeb
CVSS: 9.8 (Critical) per the NVD record, submitted by Fortinet, Inc. as CNA —CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Improper Authentication(CWE-287). Note: FortiGuard's own PSIRT advisory (FG-IR-26-158) rates this issue 8.8 (High) instead; the two scores reflect different Fortinet-sourced submissions, and NVD had not yet published an independent NIST assessment at time of writing.
Affected: FortiWeb 8.0.0 through 8.0.2, 7.6.0 through 7.6.6, 7.4.0 through 7.4.11, 7.2.0 through 7.2.12.
Fixed in: Upgrade to 8.0.3, 7.6.7, 7.4.12, or 7.2.13 or above, as applicable.
Requires a non-default configuration: A Remote Type administrator account with RADIUS authentication and the Wildcard setting enabled.
Under this configuration, FortiWeb matches any username returned by the remote authentication server against a defined admin group, allowing login with arbitrary credentials.
Successful exploitation grants full administrative access to the FortiWeb GUI/CLI.
Discovered internally during a Fortinet audit; no known exploitation.
CVE-2026-70468 — FortiManager / FortiManager Cloud
CVSS: 7.3 (High), Authentication Bypass Using an Alternate Path or Channel.
Affected: FortiManager and FortiManager Cloud 7.6.1, 7.4.3 through 7.4.5, 7.2.5 through 7.2.9 (8.0 not affected).
Fixed in: Upgrade to 7.6.2, 7.4.6, or 7.2.10 or above, as applicable.
Weaknesses reside in the FGFM protocol used for FortiManager-to-FortiGate communication
Exploitation requires the CLI option fgfm-peercert-withoutsn to be enabled, plus possession of a valid certificate.
A successful attacker can impersonate any FortiGate device managed by the affected FortiManager instance.
No known exploitation reported.
CVE-2026-70465 — FortiClient for Windows
CVSS: 7.3 (High), Buffer Copy Without Checking Size of Input.
Affected: FortiClient Windows 7.4.0 through 7.4.3, and 7.2.0 through 7.2.11 (8.0 not affected).
Fixed in: Upgrade to 7.4.4 or above, or 7.2.12 or above, as applicable.
An unauthenticated attacker positioned to alter or craft DNS responses to a targeted host can trigger the overflow via malicious packets, resulting in privilege escalation or arbitrary code execution.
Reported externally under responsible disclosure by researcher Nir Chako of Pentera; no known exploitation.
Workaround available: disabling application-based filtering in the FortiClient EMS VPN Tunnel profile.
CVE-2026-49975 — "HTTP/2 Bomb" (Apache HTTP Server component)
CVSS: 5.8 (Medium), Memory Allocation with Excessive Size Value.
Root cause is a third-party Apache HTTP Server vulnerability (Apache 2.4.17–2.4.67) affecting Fortinet products that embed the affected component.
Confirmed affected: FortiPAM (all versions through 1.9.1), FortiProxy 7.2 (all versions), 7.4.0–7.4.14, 7.6.0–7.6.6; FortiSwitchManager 7.2.0–7.2.9
Fixes: Upcoming releases for FortiPAM 1.9.2, FortiProxy 7.6.7/7.4.15, FortiSwitchManager 7.2.10; earlier FortiPAM branches (1.0–1.8) require migration to a fixed release.
Under vendor investigation: FortiOS, FortiProxy, FortiPAM, FortiSASE, FortiSwitchManager, FortiPresence.
Confirmed not impacted: FortiDDoS, FortiADC, FortiWebManager, FortiSOAR.
Exploitation triggers denial of service via crafted HTTP/2 requests exploiting HPACK compression handling; unauthenticated.
No known exploitation reported by Fortinet, though public proof-of-concept code for the underlying Apache issue has been reported by third parties.

Impact
Full administrative takeover of exposed FortiWeb web application firewalls, including the ability to alter WAF policy, disable protections, or pivot into the protected web application environment.
Impersonation of managed FortiGate devices via compromised FortiManager instances, with potential for unauthorized firewall policy changes across an enterprise's managed fleet.
Privilege escalation or remote code execution on FortiClient for Windows endpoints, enabling initial access, credential theft, or further lateral movement.
Denial of service on affected FortiPAM, FortiProxy, and FortiSwitchManager instances, potentially disrupting privileged access management and proxy services.
Potential downstream compromise of centrally managed security infrastructure given the interdependence between FortiManager and the FortiGate devices it controls.
Reputational and operational risk for organizations relying on these products in perimeter security, endpoint protection, and privileged access roles.
Detection Method
Alert on administrative logins to FortiWeb from unexpected source IPs or geographies, particularly for Remote Type accounts configured with RADIUS authentication.
Monitor FortiWeb administrative audit logs for authentication events that do not correspond to known, expected usernames.
Alert on FGFM protocol connections to FortiManager from unrecognized or unexpected certificate identities.
Monitor FortiManager logs for unexpected changes to managed FortiGate device policies that do not correlate with authorized administrative activity.
Monitor endpoint telemetry on hosts running FortiClient for Windows for crash events, unexpected process spawns, or anomalous behavior in the DNS-handling component following the receipt of malformed or unsolicited DNS responses.
Monitor DNS traffic for signs of spoofing or response manipulation targeting hosts running vulnerable FortiClient versions.
Monitor for abnormal memory or resource consumption patterns on FortiPAM, FortiProxy, and FortiSwitchManager instances consistent with HTTP/2-based resource exhaustion attacks.
Indicators of Compromise
No indicators of compromise are associated with these vulnerabilities at this time.

Recommendations
Upgrade FortiWeb to 8.0.3, 7.6.7, 7.4.12, or 7.2.13 as applicable, treating this as the highest priority given its Critical NVD rating.
Upgrade FortiManager/FortiManager Cloud to 7.6.2, 7.4.6, or 7.2.10 as applicable.
Upgrade FortiClient for Windows to 7.4.4 or 7.2.12 as applicable.
Upgrade or migrate FortiPAM, FortiProxy, and FortiSwitchManager to the fixed releases identified above once available; monitor Fortinet PSIRT for release timing on pending fixes.
Where immediate patching of FortiWeb is not feasible, disable the Wildcard setting on any Remote Type administrator account (System > Administrators in the GUI, or set wildcard disable under config system admin in the CLI).
Where immediate patching of FortiManager is not feasible, disable fgfm-peercert-withoutsn (config system global, set fgfm-peercert-withoutsn disable).
Where immediate patching of FortiClient is not feasible, disable application-based filtering in the FortiClient EMS VPN Tunnel profile.
Audit all FortiWeb Remote Type administrator accounts to identify any with the Wildcard setting enabled.
Review FortiManager CLI configurations for use of fgfm-peercert-withoutsn and validate whether it is operationally required.
Restrict administrative and management interface access to trusted networks only.
Conclusion
These four vulnerabilities collectively expose administrative, endpoint, and infrastructure layers of the Fortinet security stack, though each requires a specific condition to be exploitable. The FortiWeb authentication bypass poses the most immediate risk given its low complexity, the Critical severity assigned in its NVD record, and the level of access it grants. While no active exploitation has been reported, the low barrier to exploitation for CVE-2026-26035 in particular warrants urgent attention. We urge organizations to prioritize identifying and remediating vulnerable configurations, apply available patches promptly, and use the documented workarounds where immediate upgrades are not feasible.
References
https://fortiguard.fortinet.com/psirt/FG-IR-26-158
https://nvd.nist.gov/vuln/detail/CVE-2026-26035
https://fortiguard.fortinet.com/psirt/FG-IR-26-160
https://nvd.nist.gov/vuln/detail/CVE-2026-70468
https://fortiguard.fortinet.com/psirt/FG-IR-26-156
https://nvd.nist.gov/vuln/detail/CVE-2026-70465
https://fortiguard.fortinet.com/psirt/FG-IR-26-163
https://nvd.nist.gov/vuln/detail/CVE-2026-49975
https://cybersecuritynews.com/fortinet-authentication-vulnerabilities/