CVE-2026-70465 – Fortinet FortiWeb, FortiManager, and FortiClientWindows
“Authentication failures and a remote code execution flaw put critical Fortinet security controls at risk.”
Fortinet addresses three high-severity vulnerabilities across FortiWeb, FortiManager, and FortiClientWindows. CVE-2026-26035 allows an unauthenticated remote attacker to bypass FortiWeb authentication and access the GUI or CLI using arbitrary credentials. CVE-2026-26035 has a CVSS score of 8.8, High severity.
CVE-2026-70468 is an authentication bypass affecting FortiManager and FortiManager Cloud that can result in improper access control. It has a CVSS score of 7.3, High severity. CVE-2026-70465 is a FortiClientWindows buffer overflow that can enable arbitrary code execution through malicious DNS responses. It has a CVSS score of 7.3, High severity.
Key Details
- Affected Product
- Fortinet Forticlient
- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-120