CVE
CVE-2026-26035
0field notes · 1digest CVSS 9.8
The verdict
An authentication bypass in FortiWeb lets a remote, unauthenticated attacker log into the GUI or CLI with any random username and password. That's not a typo: any credentials work. If your FortiWeb management interface is reachable, an attacker has full admin access right now.
Patch urgency · Patch immediately
Daily digests