AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-26035

CRITICAL · CVSS 9.8 EPSS 0.51%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Fortinet FortiWeb versions 8.0.0 to 8.0.2, 7.6.0 to 7.6.6, 7.4.0 to 7.4.11, 7.2.0 to 7.2.12, and 7.0.0 to 7.0.12 are vulnerable to an improper authentication flaw, enabling remote unauthenticated attackers to gain access to the FortiWeb GUI/CLI using any username and password. This critical vulnerability poses a significant risk as it allows unauthorized control over the web application firewall, potentially leading to data breaches or service disruptions. Organizations using affected FortiWeb versions should prioritize immediate patching to mitigate this severe security threat.

CVE
CVE-2026-26035
Severity
CRITICAL
CVSS
9.8
EPSS
0.51%
Fortinet

Original NVD Description

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password