VORANT. Threat Intelligence Sign in Get the full feed

Fortinet Patches Multiple Products for Critical Flaws

elevated vulnerability technologyinfrastructure

ANSSI advisory details multiple vulnerabilities across Fortinet products including FortiOS, FortiWeb, FortiManager and FortiClient enabling RCE, privilege escalation and DoS.

CERT-FR published an advisory covering multiple vulnerabilities affecting a broad range of Fortinet products, including FortiClient for Windows, FortiManager, FortiManager Cloud, FortiOS, FortiPAM, FortiProxy, FortiSIEM, FortiSwitchManager, and FortiWeb. The flaws span several vulnerability classes: remote code execution, privilege escalation, remote denial of service, SSRF, security policy bypass, and confidentiality breaches, indicating a diverse set of underlying issues rather than a single root cause.

Eight distinct Fortinet PSIRT bulletins (FG-IR-26-156 through FG-IR-26-163) map to eight CVEs disclosed on 12 August 2026. No indication of active exploitation is provided in the advisory, and no threat actor or campaign is attributed. Given the wide product footprint—spanning network security appliances, SIEM, PAM, and endpoint client software—organizations running affected Fortinet versions should prioritize patching per vendor guidance, particularly for internet-facing management interfaces such as FortiManager and FortiProxy.

Mentioned in this report

Vulnerabilities CVE-2026-26035CVE-2026-49975CVE-2026-70465CVE-2026-70466CVE-2026-70467CVE-2026-70468CVE-2026-71407CVE-2026-71408

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1015

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free