CVE-2026-70465 – Fortinet FortiWeb, FortiManager, and FortiClientWindows

CVSS 8.1 IMPORTANT High with EoP or RCE – Expedited Deployment

“Authentication failures and a remote code execution flaw put critical Fortinet security controls at risk.”

Fortinet addresses three high-severity vulnerabilities across FortiWeb, FortiManager, and FortiClientWindows. CVE-2026-26035 allows an unauthenticated remote attacker to bypass FortiWeb authentication and access the GUI or CLI using arbitrary credentials. CVE-2026-26035 has a CVSS score of 8.8, High severity.

CVE-2026-70468 is an authentication bypass affecting FortiManager and FortiManager Cloud that can result in improper access control. It has a CVSS score of 7.3, High severity. CVE-2026-70465 is a FortiClientWindows buffer overflow that can enable arbitrary code execution through malicious DNS responses. It has a CVSS score of 7.3, High severity.

Key Details

Affected Product
Fortinet Forticlient
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
CWE Classification
CWE-120
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.