CVE-2026-26035Patch(fortinet / fortiweb)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch fortinet fortiweb systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortiweb

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 14 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 5 mentions (2026-08-13); latest day: 1
  • 17 total mentions across 5 days

Affected systems

Vendors
Products
fortiweb

Deep dive

Activity timeline17 mentions / 5d
01345Mentions · 2026-08-12: 4Mentions · 2026-08-13: 5Mentions · 2026-08-14: 3Mentions · 2026-08-16: 4Mentions · 2026-08-20: 1PoC Mentioned / Linked · 2026-08-12: 1Exploit Tool / Code · 2026-08-12: 1Patch / Workaround · 2026-08-12: 1Patch / Workaround · 2026-08-13: 5Patch / Workaround · 2026-08-14: 1Patch / Workaround · 2026-08-16: 4Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-12: 2Technical Details · 2026-08-13: 5Technical Details · 2026-08-14: 2Technical Details · 2026-08-16: 4Technical Details · 2026-08-20: 108-1208-1308-1408-1608-20
Signal classification4 categories
Patch
1270.6%
Disclosure
211.8%
General
211.8%
Exploit
15.9%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-08-124
Disclosure1Exploit1General1Patch1
2026-08-135
Patch5
2026-08-143
Disclosure1General1Patch1
2026-08-164
Patch4
2026-08-201
Patch1
Full discourse17 posts
  • KEVIntel@kev_intel
    Patch

    🚨 EARLY WARNING: Fortinet FortiWeb CVE-2026-26035. Remote. Unauthenticated. Low complexity. Login with random credentials. We have NOT seen exploitation yet. That’s the point of the warning. If you run FortiWeb, don’t wait for exploitation to start. Patch now. https://t.co/i1TpD3DMd8

    Post summary

    The tweet warns of the remotely exploitable FortiWeb CVE‑2026‑26035, indicating unauthenticated access risk, and urges immediate patching despite no active exploitation evidence.

    2311051.2K
    62 followersView on X
  • Aretiq.AI@AretiqAI
    Exploit

    ARETIQ Daily Vulnerability Bulletin — August 12, 2026 🔴 CRITICAL: CVE-2026-26035 (fortinet/fortiweb) AAS 14.9 — PoC available 🔴 CRITICAL: CVE-2026-17218 (ibm/i) AAS 12.9 — exploit available 🔴 CRITICAL: CVE-2026-73299 (microsoft/prompty) AAS 12.8 — exploit available 🔴 CRITICAL: CVE-2026-73263 (prowler-cloud/prowler) AAS 12.7 — exploit available 🔴 CRITICAL: CVE-2026-73300 (budibase/budibase) AAS 12.7 — exploit available + 2 more CRITICAL 30 vulnerabilities — CRITICAL: 7, HIGH: 23 Full bulletin: https://aretiq.ai/bulletins/2026-08-12/

    Post summary

    The bulletin lists 30 critical vulnerabilities, many with available PoCs and exploit code, but provides no evidence of active exploitation or patch information.

    00094526
    232 followersView on X
  • Cert-IST@cert_ist
    Patch

    Ce mercredi, Fortinet a annoncé des correctifs pour huit failles dans ses produits, dont CVE-2026-26035, un bug dans FortiWeb qui permet à un attaquant de se connecter à l'interface graphique ou en ligne de commande avec des identifiants aléatoires. https://tinyurl.com/bdb3pz4p

    Post summary

    Fortinet has released patches for eight vulnerabilities, including CVE‑2026‑26035, a FortiWeb flaw that permits attackers to log into the GUI or CLI using random credentials.

    02030238
    961 followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Patch

    Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468)https://rocket-boys.co.jp/security-measures-lab/fortinet-fortiweb-fortimanager-authentication-vulnerability/ "FortiWebやFortiManagerはネットワーク境界やセキュリティ機器の管理に利用されるため、対象バージョンと設定を確認し、修正版へ…"

    Post summary

    Fortinet identifies authentication vulnerabilities in FortiWeb and FortiManager (CVE-2026-26035/CVE-2026-70468) and recommends users update to the fixed versions. The notice emphasizes patching to mitigate unauthenticated login and impersonation risks.

    00011293
    3.5K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password』 CVE-2026-26035 PSIRT | FortiGuard Labs Broken access control in the RADIUS type admin group https://www.fortiguard.com/psirt/FG-IR-26-158

    Post summary

    FortiGuard Labs announced CVE-2026-26035, detailing a broken access control flaw that enables remote unauthenticated attackers to log into the Fortiweb GUI/CLI using random usernames and passwords.

    00011477
    7.0K followersView on X
  • UWillC@uwillc
    Patch

    You can log into a FortiWeb console with a random username and password. One setting makes it possible. CVE-2026-26035: admin accounts using remote RADIUS-type authentication with the wildcard option enabled will accept random credentials. Unauthenticated. GUI and CLI. Fixed in 8.0.3 / 7.6.7 / 7.4.12 / 7.2.13 (7.0 branch affected too). Until then, one line: set wildcard disable. Same batch, CVE-2026-70468: with one CLI option set and a valid certificate, an attacker can impersonate any FortiGate your FortiManager manages. CVSS 8.1. Fixed in 7.6.2 / 7.4.6 / 7.2.10. Fortinet's advisory scores it 8.8 High. NVD lists the same CVE at 9.8 Critical. The gap is the precondition: the vulnerable setting is not default. Read the precondition before you panic-patch. Is set wildcard disable in your golden config yet?

    Post summary

    The message highlights a Fortinet authentication flaw and urges users to patch or disable the vulnerable wildcard option before official updates are applied.

    0001073
    495 followersView on X
  • aMI@aMI_KUH95291
    Patch

    Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468) https://rocket-boys.co.jp/security-measures-lab/fortinet-fortiweb-fortimanager-authentication-vulnerability/

    Post summary

    Fortinet announces fixes for authentication vulnerabilities CVE-2026-26035 and CVE-2026-70468, addressing issues such as unauthenticated login and FortiGate impersonation.

    00010145
    1.9K followersView on X
  • كاسبر سكاي@KasperskyDev
    Patch

    ⚠️ ثغرة في جدار حماية الويب تُتيح تسجيل الدخول بأي بيانات اعتماد عشوائية. المعرّف : CVE-2026-26035 درجة الخطورة : 9.8 (CVSS) - Critical المنتج : FortiWeb 7.0–8.0 (wildcard RADIUS) الحل : 8.0.3 / 7.6.7 / 7.4.12 / 7.2.13 #Fortinet #CVE202626035

    Post summary

    A critical vulnerability (CVE‑2026‑26035) in FortiWeb’s RADIUS wildcard login is disclosed, with patched versions identified, but no proof‑of‑concept or active exploitation details are provided.

    01000302
    39.9K followersView on X
  • Cyber Edition@CyberEdition
    Patch

    ⚠️ Fortinet patched CVE-2026-26035, a critical FortiWeb flaw that can let remote unauthenticated attackers log in with arbitrary credentials when wildcard RADIUS authentication is enabled. Patch now or disable wildcard auth. #CyberSecurity #Fortinet Read more: https://thecyberedition.com/fortinet-patches-critical-fortiweb-flaw-allowing-unauthenticated-admin-logins/

    Post summary

    The tweet announces that Fortinet has released a patch for CVE-2026‑26035, a critical flaw in FortiWeb that permits unauthenticated administrators to log in when wildcard RADIUS authentication is enabled, urging users to apply the patch or disable the feature.

    00010110
    763 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468) https://rocket-boys.co.jp/security-measures-lab/fortinet-fortiweb-fortimanager-authentication-vulnerability/ #セキュリティ対策Lab #security #securitynews #脆弱性

    Post summary

    The text announces that Fortinet’s FortiWeb and FortiManager authentication vulnerabilities (CVE‑2026‑26035, CVE‑2026‑70468) have been fixed, confirming patch availability.

    00000195
    548 followersView on X
  • Undercode News@undercode_news
    General

    🚨 FortiWeb Authentication Claims Under Scrutiny: What Organizations Need to Know About #CVE-2026-26035 and Fortinet’s Real 2026 Security Risks -Fact Checker: ✅: 2 ❌: 3 || 2/5 → Score: 40% 🤏🏻 -Prediction: 📈 2 Positive | 📉 2 Negative https://undercodenews.com/fortiweb-authentication-claims-under-scrutiny-what-organizations-need-to-know-about-cve-2026-26035-and-fortinets-real-2026-security-risks/

    Post summary

    The tweet references a CVE and a linked article title without providing technical details, proof-of-concept, or exploitation information.

    0000034
    82 followersView on X
  • RedLegg@RedLegg
    Patch

    Security Bulletin: Broken Access Control in the RADIUS Type Admin Group in FortiWeb - FortiWeb vulnerability (CVE-2026-26035) may allow unauthenticated administrative access when a specific RADIUS wildcard configuration is enabled. Update or a... https://hubs.li/Q04s-jT-0

    Post summary

    A security bulletin reports a broken access control flaw in FortiWeb that could allow unauthenticated administrative access through a RADIUS wildcard configuration, and announces that an update is available to address the issue.

    0000055
    2.2K followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 Fortinet has patched multiple critical authentication flaws across FortiWeb, FortiManager & FortiClient. 1. CVE-2026-26035 (FortiWeb): Improper RADIUS wildcard auth lets attackers log in with random creds. 2. CVE-2026-70468 (FortiManager): Auth bypass in FGFM protocol enables FortiGate impersonation. 3. CVE-2026-70465 (FortiClient): Buffer overflow via spoofed DNS → RCE. Admins urged to patch ASAP—no active exploits yet, but risk is high.

    Post summary

    Fortinet has released patches for three critical authentication flaws across FortiWeb, FortiManager, and FortiClient, urging administrators to update immediately; no active exploits have been reported.

    0000061
    38 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    Fortinet FortiWeb users: CVE-2026-26035 (CVSS 9.8) impacts versions 7.2-8.0 with improper auth. Review deployments and patch. https://nvd.nist.gov/vuln/detail/CVE-2026-26035 https://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/QEIFlw4LG3

    Post summary

    The tweet alerts Fortinet FortiWeb users to CVE-2026-26035, a high‑severity improper‑auth vulnerability affecting versions 7.2‑8.0, and urges them to review deployments and apply patches.

    0000032
    92 followersView on X
  • Vistem Solutions@VistemSolutions
    Patch

    🚨 Fortinet FortiWeb CVE-2026-26035 Alert This vulnerability could allow remote unauthenticated attackers to access the FortiWeb GUI/CLI using random credentials, creating serious risk for exposed systems. If your organization uses FortiWeb, take action now: ✅ Review affected versions immediately ✅ Apply Fortinet’s recommended security updates ✅ Restrict GUI/CLI access to trusted networks or VPN ✅ Audit admin accounts, logs, and recent configuration changes ✅ Monitor for unusual login activity ✅ Validate MFA and access controls where available Cybersecurity isn’t just about reacting—it’s about staying ready. Vistem Solutions helps businesses strengthen security, reduce risk, and move forward with confidence. 📩 Contact us: sales@vistem.com #Cybersecurity #Fortinet #FortiWeb #CVE #VulnerabilityManagement #CyberResilience #ITSecurity #SecureInnovation #VistemSolutions #BusinessSecurity https://cvefeed.io/vuln/detail/CVE-2026-26035?utm_source=in_page&utm_medium=Vistem+Solutions%2C+Inc.&utm_campaign=publer

    Post summary

    An alert for Fortinet FortiWeb CVE-2026-26035 warns that remote unauthenticated attackers can gain GUI/CLI access with random credentials, and recommends applying vendor patches and tightening access controls.

    0000052
    84 followersView on X
  • KEVIntel@kev_intel
    General

    https://kevintel.com/CVE-2026-26035

    Post summary

    The link references CVE-2026-26035 but the provided text contains no explicit details about the vulnerability or its exploitation.

    0000082
    59 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-26035 An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6… CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-26035 #Fortinet #CyberSecurity #InfoSec

    Post summary

    Fortinet FortiWeb versions 7.6‑8.0.2 are affected by CVE-2026‑26035, an improper authentication flaw rated CVSS 9.8, with no patch available yet and a detailed analysis posted at the provided link.

    0000046
    87 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortiweb---

Explore more