【Vulnerability Alert】Fortinet FortiWeb Contains a Critical Cybersecurity Vulnerability (CVE-2026-26035)
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026081708082323 | Publication Time | 2026-08-17 08:41:26 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-08-17 08:41:26 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Fortinet FortiWeb Contains a Critical Cybersecurity Vulnerability (CVE-2026-26035) |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000012 Fortinet FortiWeb is a firewall product designed to protect web applications, with functions including anomaly detection, API protection, bot mitigation, and advanced threat analysis. Recently, Fortinet issued an advisory regarding a critical cybersecurity vulnerability (CVE-2026-26035, CVSS: 9.8). An improper authentication vulnerability exists in the administrator authentication configuration for FortiWeb using the remote RADIUS type. When certain non-default settings are used, an unauthenticated remote attacker may be able to log in to the FortiWeb GUI/CLI using a random username and password. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
FortiWeb versions 7.2.0 to 7.2.12 |
|||
|
[Recommended Actions] Please update to the following versions: FortiWeb version 7.2.13 or later, FortiWeb version 7.4.12 or later, FortiWeb version 7.6.7 or later, FortiWeb version 8.0.3 or later |
|||
|
[Reference] |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





