Fortinet disclosed CVE-2026-70468, a high-severity authentication bypass flaw in FortiManager and FortiManager Cloud that could let an unauthenticated remote attacker gain improper access to vulnerable systems. The issue is tracked as CWE-288 and carries a CVSS v3.1 score of 8.1. Affected versions include FortiManager and FortiManager Cloud 7.6.1, 7.4.3 through 7.4.5, and 7.2.5 through 7.2.9, and Fortinet has directed customers to install fixed releases and vendor patches.
A related Canadian Centre for Cyber Security notice, AV26-812, said multiple Fortinet products are affected, naming FortiClientWindows, FortiManager, and FortiManager Cloud across several version branches. The advisory did not publish exploit details, but urged administrators to review Fortinet PSIRT and FortiGuard guidance and apply updates as they become available, underscoring the need for rapid patching across exposed management infrastructure.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-812 stating that Fortinet products were affected by a vulnerability. The notice listed affected versions of FortiClientWindows, FortiManager, and FortiManager Cloud and directed users to review Fortinet PSIRT and FortiGuard Labs resources and apply updates as available.
The CVE entry for CVE-2026-70468 was published, documenting an authentication bypass flaw in FortiManager and FortiManager Cloud with a CVSS v3.1 score of 8.1. Affected versions listed include FortiManager and FortiManager Cloud 7.6.1, 7.4.3 through 7.4.5, and 7.2.5 through 7.2.9.
Fortinet published advisory FG-IR-26-160 for CVE-2026-70468, describing a high-severity authentication bypass vulnerability affecting FortiManager and FortiManager Cloud. The issue is remotely exploitable, mapped to CWE-288, and Fortinet advised customers to update to fixed versions and review access controls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.