CVE-2026-70468Patch(fortinet / fortimanager)

MEDIUMCVSS 8.1 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch fortinet fortimanager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortimanager
  • fortimanager_cloud

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-08-13); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
fortimanagerfortimanager_cloud

1 version affected across 2 products

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-08-12: 1Mentions · 2026-08-13: 3Mentions · 2026-08-16: 3Mentions · 2026-08-20: 1PoC Mentioned / Linked · 2026-08-20: 1Active Exploitation · 2026-08-13: 1Patch / Workaround · 2026-08-13: 2Patch / Workaround · 2026-08-16: 3Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-12: 1Technical Details · 2026-08-13: 2Technical Details · 2026-08-16: 1Technical Details · 2026-08-20: 108-1208-1308-1608-20
Signal classification3 categories
Patch
675.0%
Disclosure
112.5%
Active Exploitation
112.5%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-121
Disclosure1
2026-08-133
Active Exploitation1Patch2
2026-08-163
Patch3
2026-08-201
Patch1
Full discourse8 posts
  • ねこさん⚡(ΦωΦ)@catnap707
    Patch

    Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468)https://rocket-boys.co.jp/security-measures-lab/fortinet-fortiweb-fortimanager-authentication-vulnerability/ "FortiWebやFortiManagerはネットワーク境界やセキュリティ機器の管理に利用されるため、対象バージョンと設定を確認し、修正版へ…"

    Post summary

    The article focuses on identifying and patching authentication vulnerabilities in Fortinet FortiWeb and FortiManager, urging users to verify impacted versions and apply the available fix.

    00011293
    3.5K followersView on X
  • UWillC@uwillc
    Patch

    You can log into a FortiWeb console with a random username and password. One setting makes it possible. CVE-2026-26035: admin accounts using remote RADIUS-type authentication with the wildcard option enabled will accept random credentials. Unauthenticated. GUI and CLI. Fixed in 8.0.3 / 7.6.7 / 7.4.12 / 7.2.13 (7.0 branch affected too). Until then, one line: set wildcard disable. Same batch, CVE-2026-70468: with one CLI option set and a valid certificate, an attacker can impersonate any FortiGate your FortiManager manages. CVSS 8.1. Fixed in 7.6.2 / 7.4.6 / 7.2.10. Fortinet's advisory scores it 8.8 High. NVD lists the same CVE at 9.8 Critical. The gap is the precondition: the vulnerable setting is not default. Read the precondition before you panic-patch. Is set wildcard disable in your golden config yet?

    Post summary

    The post explains that CVE‑2026‑26035 and CVE‑2026‑70468 allow unauthenticated access and impersonation, provides CVSS scores, patches and a simple configuration workaround, but does not report active exploitation.

    0001073
    495 followersView on X
  • aMI@aMI_KUH95291
    Patch

    Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468) https://rocket-boys.co.jp/security-measures-lab/fortinet-fortiweb-fortimanager-authentication-vulnerability/

    Post summary

    Fortinet has released patches for CVE-2026-26035 and CVE-2026-70468 to address authentication vulnerabilities that could enable unauthorized login and FortiGate impersonation.

    00010145
    1.9K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468) https://rocket-boys.co.jp/security-measures-lab/fortinet-fortiweb-fortimanager-authentication-vulnerability/ #セキュリティ対策Lab #security #securitynews #脆弱性

    Post summary

    A Japanese security notice announces the patch for FortiWeb and FortiManager authentication vulnerabilities (CVE-2026-26035/CVE-2026-70468), highlighting risks of unauthenticated access and FortiGate impersonation.

    00000195
    548 followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 Fortinet has patched multiple critical authentication flaws across FortiWeb, FortiManager & FortiClient. 1. CVE-2026-26035 (FortiWeb): Improper RADIUS wildcard auth lets attackers log in with random creds. 2. CVE-2026-70468 (FortiManager): Auth bypass in FGFM protocol enables FortiGate impersonation. 3. CVE-2026-70465 (FortiClient): Buffer overflow via spoofed DNS → RCE. Admins urged to patch ASAP—no active exploits yet, but risk is high.

    Post summary

    Fortinet has released patches for three critical CVEs affecting FortiWeb, FortiManager, and FortiClient, detailing the vulnerabilities and urging admins to apply updates immediately; no active exploitation has been reported yet.

    0000061
    38 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-70468 (CVSS 8.1) is an auth bypass affecting Fortinet FortiManager 7.6.1, 7.4.3-7.4.5, 7.2.5-7.2.9. Review deployments and apply updates: https://nvd.nist.gov/vuln/detail/CVE-2026-704… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/23Rs6pEB4p

    Post summary

    The tweet announces a high‑severity authentication bypass in FortiManager, provides affected versions, and urges users to apply the available patch.

    0000032
    92 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    It is possible to see elevated activities targeting Fortinet FortiManager and FortiManager Cloud (CVE-2026-70468) https://vuldb.com/vuln/388992/cti

    Post summary

    The text reports observed elevated activity against Fortinet FortiManager and FortiManager Cloud for CVE‑2026‑70468, implying active exploitation, but it contains no PoC, exploit code, patch information, or technical details.

    00000136
    2.3K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-70468 A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7… CVSS 8.1 Full analysis → https://sec.kaitan.id/cves/CVE-2026-70468 #Fortinet #CyberSecurity #InfoSec

    Post summary

    Fortinet disclosed CVE-2026-70468, an authentication bypass vulnerability in FortiManager 7.6.1 with a CVSS score of 8.1. The post offers a link to a full analysis but does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0000043
    87 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortimanager---
Appfortinetfortimanager7.6.1--
Appfortinetfortimanager_cloud---
Appfortinetfortimanager_cloud7.6.1--

Explore more