Threat Advisory

FortiWeb Vulnerability Allows Random Login

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple critical authentication bypass, buffer overflow, and evasion vulnerabilities have been identified across various enterprise management, endpoint, and perimeter protection platforms. These flaws carry severe impacts ranging from unauthenticated remote administrative access and device impersonation to arbitrary code execution and service denial, with CVSS scores reaching up to 9.8. Exploitation risks are notably elevated due to the minimal complexity required to abuse these flaws, making affected infrastructure prime targets for perimeter compromise and initial access. Organizations relying on these deployment lines must act rapidly to audit configurations and implement corrective updates.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple critical authentication bypass, buffer overflow, and evasion vulnerabilities have been identified across various enterprise management, endpoint, and perimeter protection platforms. These flaws carry severe impacts ranging from unauthenticated remote administrative access and device impersonation to arbitrary code execution and service denial, with CVSS scores reaching up to 9.8. Exploitation risks are notably elevated due to the minimal complexity required to abuse these flaws, making affected infrastructure prime targets for perimeter compromise and initial access. Organizations relying on these deployment lines must act rapidly to audit configurations and implement corrective updates.[emaillocker id="1283"]

  • CVE-2026-26035:An improper authentication vulnerability exists within the web application firewall's administrative login mechanism when configured for remote RADIUS authentication with wildcard settings enabled. Affected components include multiple branches of the web application security software. Exploitation allows an unauthenticated remote attacker to gain full GUI and CLI administrative access using arbitrary credentials, resulting in total system compromise. The low operational complexity creates a high risk of immediate opportunistic exploitation.
  • CVE-2026-70468:An authentication bypass vulnerability via an alternate path or channel exists within the management protocol used for centralized firewall administration, bearing a CVSS score of 8.1. Affected components encompass enterprise security management and cloud management platforms using specific CLI configurations and valid certificates. Successful exploitation allows an attacker to impersonate managed firewall appliances, enabling broad unauthorized manipulation of network-wide security policies.
  • CVE-2026-70465:A classic buffer overflow vulnerability affects the Windows endpoint security client software. The flaw resides in the handling of incoming network traffic, specifically impacting client versions within the 7.2 and 7.4 release branches. An unauthenticated attacker positioned to intercept or spoof DNS responses can deliver crafted network packets to execute arbitrary code with elevated privileges on target endpoints.
  • CVE-2026-70466:An incomplete input validation flaw leading to WAF evasion exists within the web application firewall content-encoding processing logic. Affected components involve perimeter application security systems processing modified input streams. Exploitation allows attackers to craft HTTP payloads that bypass active inspection policies, exposing underlying web applications to unmonitored attack vectors.
  • CVE-2026-70467:A server-side request forgery vulnerability impacts security information and event management server software. The flaw is present across multiple major releases of the SIEM platform infrastructure. An authenticated attacker can leverage this flaw to induce the server into initiating unauthorized HTTP requests, enabling internal network scanning, access to restricted local resources, and secondary service exploitation.
  • CVE-2026-71407:A stack-based buffer overflow vulnerability resides within the explicit proxy web access process of the enterprise firewall operating system. The vulnerability affects instances configured with Kerberos authentication alongside SOCKS explicit proxying. An attacker can transmit specially crafted socket requests to trigger a buffer overflow, potentially leading to arbitrary code execution or process crashes.
  • CVE-2026-71408:An allocation of resources without limits vulnerability exists within the web management interface of the enterprise operating system. The flaw affects multiple active firewall operating system release branches. Exploitation allows a remote attacker to initiate slow HTTP request streams, causing exhaustion of web server thread pools and resulting in a persistent denial-of-service state for administrative interfaces.
  • CVE-2026-49975:An HTTP/2 memory exhaustion vulnerability affects the underlying web server components integrated into web application firewalls and cloud security platforms. The issue stems from improperly managed HPACK compression bombs combined with flow-control stalls. Remote attackers can trigger excessive memory allocation, crashing security services and disrupting web application delivery.

Prompt firmware updates and targeted configuration hardening are necessary to secure perimeter networks, centralized management servers, and endpoints against potential exploitation. Organizations should immediately isolate administrative web interfaces, enforce strict authentication parameters, and deploy updated vendor software releases across all impacted product lines to maintain operational integrity.

RECOMMENDATION:

  • We recommend you to update FortiWeb to version 8.0.3, 7.6.7, 7.4.12, or 7.2.13.
  • We recommend you to update FortiManager to version 7.6.2, 7.4.6, or 7.2.10.
  • We recommend you to update FortiClient to version above 7.4.3 and 7.2.11.

REFERENCES:

The following reports contain further technical details:
https://cybersecuritynews.com/fortinet-authentication-vulnerabilities/

[/emaillocker]
crossmenu