PatchDayAlert

CVE

CVE-2026-26035

0field notes · 1digest CVSS 9.8

The verdict

An authentication bypass in FortiWeb lets a remote, unauthenticated attacker log into the GUI or CLI with any random username and password. That's not a typo: any credentials work. If your FortiWeb management interface is reachable, an attacker has full admin access right now.

Patch urgency · Patch immediately


Daily digests