Fortinet FortiWeb and FortiClient flaws exploited by attackers to gain access and execute arbitrary code

17 Aug 2026

Fortinet recently disclosed two high-severity flaws in FortiWeb and FortiClient for Windows that are allowing attackers to gain unauthorized access and execute arbitrary code.

 

Through this blog, we will understand what the vulnerabilities are about, the threats they pose, and what organizations can do to defend against them.

About the vulnerabilities

Vendor + components affected 

CVE/CVSS 

About  

Affected systems 

 

Microsoft +  

FortiWeb Web Application Firewall (WAF) 

FortiClient for Windows 

CVE-2026-26035/9.8 (Critical) 

 

CVE-2026-70465/8.1 (High) 

CVE-2026-26035 is an improper authentication vulnerability 

 

CVE-2026-70465 is a buffer overflow vulnerability affecting FortiClient for Windows. 

 

Affected Versions: 

FortiWeb 8.0.0 through 8.0.2 
FortiWeb 7.6.0 through 7.6.6 
FortiWeb 7.4.0 through 7.4.11 
FortiWeb 7.2.0 through 7.2.12 
FortiWeb 7.0.0 through 7.0.12 

 

 

Fixed Versions: 

FortiWeb 8.0.3 
FortiWeb 7.6.7 
FortiWeb 7.4.12 
FortiWeb 7.2.13 

 

 

Affected Versions: 

FortiClient 7.2.0 through 7.2.11 
FortiClient 7.4.0 through 7.4.3 

 

 

 

 

The threat posed by the vulnerabilities

CVE-2026-26035 -FortiWeb authentication bypass

This flaw affects the FortiWeb admin login when RADIUS authentication is configured with the wildcard option.

 

Because of this flaw, an attacker may be able to bypass the authentication check and log in with made up credentials.

 

An attacker can exploit this vulnerability to:

 

  • Gain unauthorized access to FortiWeb administrative interfaces
  • Bypass authentication without valid credentials
  • Modify security policies and configurations
  • Potentially cause a compromise of protected web applications
  • Gain administrative control over FortiWeb appliances
  • Move laterally within the environment

 

CVE-2026-70465 – FortiClient Windows code execution

This buffer overflow flaw affects FortiClient for Windows. It can be triggered through specially crafted DNS responses. An attacker who can manipulate DNS traffic to a vulnerable endpoint could exploit FortiClient to run malicious code on the endpoint.

 

An attacker can exploit the vulnerability to:

 

  • Remotely execute malicious code on vulnerable Windows endpoints
  • Deploy malware or ransomware
  • Cause a compromise of endpoint through DNS spoofing attacks
  • Steal data and credentials
  • Laterally move across compromised endpoints

Official mitigation guide

CVE-2026-26035 – FortiWeb – Disable the wildcard option for Remote RADIUS administrator authentication if immediate patching is not possible.

 

CVE-2026-70465 – FortiClient for Windows –

  • Upgrade to the latest FortiClient release provided by Fortinet.
  • Use trusted DNS resolvers.
  • Implement DNS security controls to prevent spoofing.
  • Deploy encrypted DNS where applicable.
  • Restrict exposure to untrusted networks.

SharkStriker’s Recommendation

  • Immediately upgrade FortiWeb and FortiClient installations to the latest supported versions.
  • Review FortiWeb deployments using Remote RADIUS administrator authentication.
  • Disable the wildcard option on FortiWeb where patching cannot be immediately performed.
  • Restrict access to FortiWeb management interfaces to trusted administrative networks only.
  • Review administrator authentication logs for signs of unauthorized access attempts.
  • Ensure DNS traffic is routed through trusted internal or reputable external DNS services.
  • Implement DNS filtering, monitoring, and anti-spoofing controls.
  • Monitor endpoints for suspicious process execution, DNS activity, and indicators of compromise.
  • Validate asset exposure and identify vulnerable Fortinet products across the environment.
  • Conduct threat hunting for suspicious administrative access and DNS-based exploitation attempts.

SharkStriker’s Action

  • Intelligence validation completed.
  • Customer impact assessment initiated.
  • Advisory prepared for affected customers.
  • Asset identification recommended for FortiWeb and FortiClient deployments.
  • Detection engineering team notified to review monitoring coverage.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE