Critical severity9.8NVD Advisory· Published Aug 12, 2026· Updated Sep 8, 2026
CVE-2026-26035
CVE-2026-26035
Description
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- fortiguard.fortinet.com/psirt/FG-IR-26-158nvdVendor AdvisoryMitigation
News mentions
4- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and MoreThe Hacker News · Aug 17, 2026
- Cyber Security Weekly Newsletter – Outlook RCE, Palo Alto, Cisco 0-day and Windows 0-Day Flaws +20 StoriesCyber Security News · Aug 16, 2026
- Fortinet Patches Multiple Authentication Vulnerabilities in FortiWeb, FortiManager, and FortiClientCyber Security News · Aug 13, 2026
- Fortinet Patches Authentication Flaws in FortiWeb and FortiManagerSecurityWeek · Aug 13, 2026