Multiple Vulnerabilities in Fortinet FortiWeb, FortiClient Windows, FortiManager, and FortiManager Cloud
18 August 2026
Attackers can exploit multiple vulnerabilities in Fortinet FortiWeb, FortiClient Windows, FortiManager, and FortiManager Cloud to bypass authentication, gain unauthorised access or execute arbitrary code. Patch promptly.
Background
Fortinet has released security updates to address multiple vulnerabilities (CVE-2026-26035, CVE-2026-70465, and CVE-2026-70468) affecting FortiWeb, FortiClient for Windows, and FortiManager, as part of Fortinet's Security Patch Day in August 2026.
These vulnerabilities have a Common Vulnerability Scoring System (CVSS v3.1) score of: CVE-2026-26035 at 8.8, CVE-2026-70465 and CVE-2026-70468 at 7.3, out of 10.
Impact
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-26035: Due to an improper authentication vulnerability in the FortiWeb remote radius type admin authentication configured with specific, non-default settings, an unauthenticated attacker could login into the FortiWeb GUI/CLI with a random username and password to gain unauthorised access to the affected system.
CVE-2026-70465: Due to a buffer overflow vulnerability in FortiClient for Windows, an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host could execute arbitrary code via malicious packets on the affected system.
CVE-2026-70468: Due to an authentication bypass using an alternate path or channel vulnerability in FortiManager and FortiManager Cloud, an unauthenticated attacker could impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate.
Affected Products
These vulnerabilities affect the following Fortinet products and versions:
For CVE-2026-26035 (FortiWeb):
FortiWeb 8.0: versions 8.0.0 through 8.0.2
FortiWeb 7.6: versions 7.6.0 through 7.6.6
FortiWeb 7.4: versions 7.4.0 through 7.4.11
FortiWeb 7.2: versions 7.2.0 through 7.2.12
For CVE-2026-70465 (FortiClient Windows):
FortiClient Windows 7.4: versions 7.4.0 through 7.4.3
FortiClient Windows 7.2: versions 7.2.0 through 7.2.11
For CVE-2026-70468 (FortiManager and FortiManager Cloud):
FortiManager 7.6: version 7.6.1
FortiManager 7.4: versions 7.4.3 through 7.4.5
FortiManager 7.2: versions 7.2.5 through 7.2.9
FortiManager Cloud 7.6: version 7.6.1
FortiManager Cloud 7.4: versions 7.4.3 through 7.4.5
FortiManager Cloud 7.2: versions 7.2.5 through 7.2.9
Recommendations
Users and administrators of affected products are advised to update to the latest versions promptly.
Mitigation
As an interim measure, the following mitigations are available:
For CVE-2026-26035: Disable the Wildcard option on Remote RADIUS-type administrator accounts.
For CVE-2026-70465: Disable application-based filtering in the FortiClient EMS VPN configuration.
For CVE-2026-70468: Disable the fgfm-peercert-withoutsn option via the CLI.
References
https://fortiguard.fortinet.com/psirt/FG-IR-26-158
https://fortiguard.fortinet.com/psirt/FG-IR-26-156
https://fortiguard.fortinet.com/psirt/FG-IR-26-160
https://nvd.nist.gov/vuln/detail/CVE-2026-26035
