York Computer logo York Computer
Managed IT & Security
Cybersecurity News

Fortinet Patches Login Bypass Flaws in FortiWeb, FortiManager and FortiClient — Patch Now

York Computer

On Wednesday, Fortinet released patches for eight vulnerabilities across its product line — including high-severity authentication bugs that could let an attacker log into a FortiWeb firewall with a random username and password, or impersonate any FortiGate firewall managed by FortiManager. If your business uses a Fortinet firewall, VPN, or the FortiClient endpoint agent (very common in small-business networks), your IT provider needs to be on top of this today.

What Fortinet actually fixed

Fortinet on Wednesday announced patches for eight vulnerabilities across its products, including high-severity authentication bugs in FortiWeb and FortiManager. The three that matter most for small and mid-sized businesses:

**FortiWeb login bypass (CVE-2026-26035).** In FortiWeb, the company resolved an improper authentication issue impacting deployments configured with specific, non-default settings. A remote, unauthenticated attacker could exploit the flaw to log in to the FortiWeb GUI/CLI with a random username and password. The flaw carries a CVSS score in the 8.8-to-9.8 range depending on the source, reflecting just how easy it would be to abuse in the wrong configuration. The bad configuration is a wildcard admin setting used with remote RADIUS authentication — it's off by default, but plenty of shops turn it on for convenience.

**FortiManager impersonation (CVE-2026-70468).** The FortiManager vulnerability is an authentication bypass issue that allows remote attackers to impersonate any FortiGate device managed by FortiManager. It requires a specific CLI option to be set and for the attacker to have a valid certificate. If those conditions are met, an attacker could impersonate any FortiGate device under that FortiManager's management, potentially manipulating firewall policies at scale.

**FortiClient for Windows buffer overflow (CVE-2026-70465).** Fortinet also patched a high-severity buffer overflow bug in FortiClient for Windows that could allow unauthenticated attackers who can modify or craft DNS responses to execute arbitrary code. FortiClient is the VPN/endpoint agent many businesses install on staff laptops.

Is this being exploited yet?

As of the advisories, no. As of the advisory's publication, Fortinet has not observed active exploitation of the issue in the wild, but given the low complexity of the attack, that could change quickly.

That's the pattern with Fortinet bugs — advisory drops, proof-of-concept code appears within days, mass scanning starts within a week or two. Fortinet perimeter devices have been repeatedly hit by ransomware crews and state-sponsored actors over the past two years, so treat these as urgent even without a confirmed exploit.

For context on how fast the window closes: earlier this year, Arctic Wolf warned of a "new cluster of automated malicious activity" involving unauthorized firewall configuration changes on Fortinet FortiGate devices, commencing on January 15, 2026, sharing similarities with a December 2025 campaign in which malicious SSO logins on FortiGate appliances were recorded against the admin account.

What your managed IT provider should be doing this week

If Fortinet is anywhere in your stack, your MSP should already be working through this checklist:

- **Inventory** every FortiWeb, FortiManager, FortiGate, and FortiClient install — including version numbers. You can't patch what you can't see. - **Apply Fortinet's patches** on FortiWeb, FortiManager, and FortiClient for Windows on the schedule Fortinet published. - **Audit FortiWeb admin configs** for the wildcard RADIUS setting. If it's on and you don't have a specific reason for it, turn it off. - **Restrict management interfaces** so the FortiWeb and FortiManager GUIs are not exposed to the public internet — trusted internal IPs or an out-of-band management network only. - **Enforce MFA** on every admin account on every Fortinet appliance. - **Pull the logs** from the past 30 days and look for unexpected admin logins, new admin accounts, or config changes.

This is exactly the type of ongoing perimeter and patch discipline that's baked into York Computer's managed IT services — you shouldn't be finding out about a vendor CVE from a news article; your provider should be telling you it's already patched. If you already have an internal IT person who's swamped, co-managed IT support can handle the patch cycles and after-hours firewall work alongside them.

What York Businesses Should Do

Fortinet gear is common in York County dental practices, manufacturing shops, and professional services offices — often installed years ago and quietly running in a closet. If nobody has logged into your firewall's admin panel in the last month, that's the problem you need to solve this week.

Sources

Worried whether your business is exposed to this? Talk to York Computer.

Managed IT & cybersecurity for York County small businesses.

← Back to all articles