Fortinet Product Security Update Advisory
Overview
Fortinet has released security updates to address vulnerabilities in its products. Users of these products should update to the latest version.
Affected Products and Vulnerabilities
- CVE-2026-26035: An improper authentication vulnerability occurring in FortiWeb’s Remote RADIUS Type administrator authentication. This affects certain builds of FortiWeb versions 7.2, 7.4, 7.6, And 8.0.
- CVE-2026-70465: A heap overflow vulnerability caused by a lack of size validation in the FortiClient Windows kernel driver. This affects certain builds of FortiClient Windows versions 7.2 And 7.4.
- CVE-2026-70468: A vulnerability that allows authentication to be bypassed in the FGFM (Authentication Protocol) of FortiManager and FortiManager Cloud. The affected versions include certain builds of FortiManager and FortiManager Cloud versions 7.2, 7.4, And 7.6.
Patch Information
Vulnerability Patches have been provided via the latest updates. Each product must be updated to the announced patch version or later.
- CVE-2026-26035: FortiWeb 7.2.13 Or later, 7.4.12 Or later, 7.6.7 Or later, 8.0.3 Or later.
- CVE-2026-70465: FortiClient for Windows 7.2.12 And later, 7.4.4 And later.
- CVE-2026-70468: FortiManager and FortiManager Cloud 7.2.10 Or later, 7.4.6 Or later, 7.6.2 Or later.