Fortinet has rolled out fixes for a batch of authentication-related vulnerabilities across its FortiWeb, FortiManager, and FortiClient product lines, urging administrators to patch quickly given the sensitivity of the affected systems. The most severe of the bunch, tracked as CVE-2026-26035, sits in FortiWeb’s login mechanism and carries a CVSS score in the 8.8-to-9.8 range depending on the source, reflecting just how easy it would be to abuse in the wrong configuration. According to Fortinet’s advisory, the flaw is an improper authentication issue (CWE-287) that surfaces when a FortiWeb administrator account is configured for Remote RADIUS Type authentication with the “wildcard” setting turned on. Under...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!