Close Menu
NCIJ Network NCIJ Network
    What's Hot

    I went curtain shopping during a Kyiv air raid. And not because I’m ‘resilient’ | Diana Berg

    October 2, 2026

    More than half of Europe faced intense summer heat stress, EU monitor says

    October 2, 2026

    Tim Heidecker Is Bringing His Joe Rogan Parody Show to The Onion

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • I went curtain shopping during a Kyiv air raid. And not because I’m ‘resilient’ | Diana Berg
    • More than half of Europe faced intense summer heat stress, EU monitor says
    • Tim Heidecker Is Bringing His Joe Rogan Parody Show to The Onion
    • How Financial Services Companies Can Modernize Their Software Supply Chain
    • Core Lightning Warns of Attacks on Unpatched Nodes
    • This common mistake can add nearly 7 points to your blood pressure reading
    • Wind turbine taller than the Eiffel Tower aims to boost German electricity production
    • India: Modi Faces Protests Over Election Commission Scandal
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 13, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Fortinet on Wednesday announced patches for eight vulnerabilities across its products, including high-severity authentication bugs in FortiWeb and FortiManager.

    In FortiWeb, the company resolved an improper authentication issue impacting deployments configured with specific, non-default settings.

    A remote, unauthenticated attacker could exploit the flaw, tracked as CVE-2026-26035, “to log in to the FortiWeb GUI/CLI with a random username and password,” Fortinet explains.

    The weakness is associated with the wildcard setting for administrator accounts, which is disabled by default. When it is enabled, the system will match any username on a remote server with the Remote User account.

    “When wildcard is enabled, and if you have defined a group name in the Admin User Group (User > User Group > Admin Group), then the system will match the users on the remote server whose group name value is the same as you defined,” Fortinet explains.

    CVE-2026-26035 was patched in FortiWeb versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. As a workaround, the company recommends disabling the wildcard setting.

    Advertisement. Scroll to continue reading.

    The FortiManager vulnerability, tracked as CVE-2026-70468, is an authentication bypass issue that allows remote attackers to impersonate any FortiGate device managed by FortiManager. It requires a specific CLI option to be set and for the attacker to have a valid certificate.

    Fortinet also patched a high-severity buffer overflow bug (CVE-2026-70465) in FortiClient for Windows that could allow unauthenticated attackers who can modify or craft DNS responses to execute arbitrary code.

    On Wednesday, the company also resolved medium- and low-severity security defects in FortiWeb WAF, FortiOS, and FortiSIEM, and published an advisory detailing the impact of CVE-2026-49975, the HTTP/2 Bomb attack affecting Apache HTTP Server.

    Fortinet makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found on the company’s PSIRT advisories page.

    Related: Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

    Related: Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

    Related: SharePoint Vulnerability Exploited Shortly After PoC Release

    Related: Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

    Authentication flaws FortiManager Fortinet FortiWeb Patches
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    How Financial Services Companies Can Modernize Their Software Supply Chain

    Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader

    Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass

    Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

    Alleged KillSec Ransomware Mastermind a 16-Year-Old

    ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    I went curtain shopping during a Kyiv air raid. And not because I’m ‘resilient’ | Diana Berg

    October 2, 2026

    More than half of Europe faced intense summer heat stress, EU monitor says

    October 2, 2026

    Tim Heidecker Is Bringing His Joe Rogan Parody Show to The Onion

    October 2, 2026

    How Financial Services Companies Can Modernize Their Software Supply Chain

    October 2, 2026
    Latest Posts

    Max Miller Continues to Resist Pressure to Drop Out as Deadline Looms

    August 7, 2026

    Houthi attacks kill at least 10 in Yemen as rebels target oil-rich Marib

    August 8, 2026

    Scientists find unexpected life on Ötzi the Iceman’s 5,300-year-old body

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    I went curtain shopping during a Kyiv air raid. And not because I’m ‘resilient’ | Diana Berg

    October 2, 2026

    More than half of Europe faced intense summer heat stress, EU monitor says

    October 2, 2026

    Tim Heidecker Is Bringing His Joe Rogan Parody Show to The Onion

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.