cbcvebase.
CVE-2026-26035
published 2026-08-12

CVE-2026-26035: An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through…

PriorityP272critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.75%
53.1th percentile
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password

Affected

11 ranges
VendorProductVersion rangeFixed in
fortinetfortinet——
fortinetfortiweb——
fortinetfortiweb7.0.0 – 7.0.12—
fortinetfortiweb>= 7.2.0 < 7.2.137.2.13
fortinetfortiweb7.2.0 – 7.2.12—
fortinetfortiweb>= 7.4.0 < 7.4.127.4.12
fortinetfortiweb7.4.0 – 7.4.11—
fortinetfortiweb>= 7.6.0 < 7.6.77.6.7
fortinetfortiweb7.6.0 – 7.6.6—
fortinetfortiweb>= 8.0.0 < 8.0.38.0.3
fortinetfortiweb8.0.0 – 8.0.2—
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.