DIRAS TAKE
Urgent: treat this as high priority because the issue lets unauthenticated actors access management interfaces without credentials, exposing full device control. Immediately limit exposure of FortiWeb management ports and follow vendor guidance.
What is CVE-2026-26035?
A remote unauthenticated attacker can log in to Fortinet FortiWeb's management GUI or CLI, gaining administrative access, under CVE-2026-26035. The flaw affects FortiWeb 8.0.0–8.0.2 and multiple 7.x releases (7.6.0–7.6.6, 7.4.0–7.4.11, 7.2.0–7.2.12, 7.0.0–7.0.12). Exploitation requires only network access to the FortiWeb management interface; no valid credentials or user interaction is required according to the vendor description of the issue. The weakness is classified as CWE-287 (Improper Authentication).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Fortinet FortiWeb are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 8.x | 8.0.0 – 8.0.2 | |
| 7.x | 7.6.0 – 7.6.6 | |
| 7.x | 7.4.0 – 7.4.11 | |
| 7.x | 7.2.0 – 7.2.12 | |
| 7.x | 7.0.0 – 7.0.12 |
Is CVE-2026-26035 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-26035
- Isolate FortiWeb management interfaces from untrusted networks and block port access from the internet.
- Restrict administrative access to trusted IPs or VPN-only access and enable strong network-level controls.
- Monitor administration and authentication logs for unexpected successful logins and anomalous activity.
- Follow Fortinet's official guidance and apply vendor patches or updates as soon as they are released.
Frequently asked questions
Is CVE-2026-26035 being actively exploited?
There are no public reports of exploitation of CVE-2026-26035 as of 2026-09-29.
Which FortiWeb versions are affected by CVE-2026-26035?
FortiWeb 8.0.0–8.0.2 and FortiWeb 7.x releases 7.6.0–7.6.6, 7.4.0–7.4.11, 7.2.0–7.2.12, and 7.0.0–7.0.12 are listed as affected.
Is there a patch for CVE-2026-26035?
No patch is listed for CVE-2026-26035 in the provided facts; affected entries show no fixed versions.
Does CVE-2026-26035 require authentication?
No; the vulnerability permits an unauthenticated remote actor to log in to the FortiWeb GUI or CLI without valid credentials.
References
- nvd.nist.gov/vuln/detail/CVE-2026-26035
- cve.org/CVERecord?id=CVE-2026-26035
- fortiguard.fortinet.com/psirt/FG-IR-26-158
- All Fortinet CVEs on CVE Radar
- CVEs published in September 2026