BoletimSecAugust 14, 2026🇵🇹Translated from Portuguese

Fortinet Patches Critical Authentication Bypass in FortiWeb Allowing Login with Random Credentials

Fortinet has issued patches for several vulnerabilities affecting its FortiWeb, FortiManager, and FortiClient products. The updates address flaws that could enable unauthorized administrative access without valid credentials and allow code execution on Windows systems.

The primary vulnerability, identified as CVE-2026-26035, impacts FortiWeb and received a CVSS score of 8.8. It manifests when administrative accounts using remote RADIUS authentication are configured with the wildcard option, a setting that is not enabled by default. In this scenario, a remote unauthenticated attacker can bypass authentication entirely and access either the graphical user interface or the command-line interface by entering any random username and password combination.

Once authenticated, the attacker obtains full administrative privileges over the web application firewall, allowing complete control of security policies and traffic inspection rules. The flaw affects multiple FortiWeb release lines, specifically versions 8.0, 7.6, 7.4, 7.2, and 7.0. Fixed releases are now available: 8.0.3, 7.6.7, 7.4.12, and 7.2.13.

At the time of disclosure, there were no indications of active exploitation targeting the authentication bypass issues. Nevertheless, the potential for unauthenticated remote administrative access makes prompt updates a high priority for any exposed FortiWeb appliances that protect critical network segments.

Related articles

HispasecVulnerabilities & Exploits

Critical GeoServer Vulnerability CVE-2024-36401 Actively Exploited for Unauthenticated Remote Code Execution

The CVE-2024-36401 flaw in GeoServer and its GeoTools library allows attackers to achieve remote code execution without authentication by abusing property name expressions interpreted as XPath. Active exploitation has already led to confirmed intrusions involving initial access, lateral movement, and persistence with tools such as China Chopper web shells. Multiple OGC endpoints including WFS GetFeature, WMS GetMap, and WPS Execute are affected when exposed to the internet. Patches are available in GeoServer versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2. Organizations unable to patch immediately can mitigate risk by removing the gt-complex JAR file, though this may break functionality. Additional defenses include restricting internet exposure through IP allowlisting, VPNs, and reverse proxies while monitoring logs for anomalous requests. Any previously exposed instances should be treated as potentially compromised, with full incident response including credential rotation and host forensics recommended.

HispasecVulnerabilities & Exploits

Critical GeoServer Vulnerability CVE-2024-36401 Actively Exploited for Unauthenticated Remote Code Execution

The vulnerability CVE-2024-36401 in GeoServer is already being exploited in real-world attacks and enables remote code execution without authentication. The flaw stems from how GeoServer and its GeoTools library interpret certain property names, allowing malicious XPath expressions via commons-jxpath in default configurations. Attackers can abuse multiple OGC endpoints including WFS GetFeature and GetPropertyValue, WMS GetMap, GetFeatureInfo and GetLegendGraphic, plus WPS Execute to gain initial access. Observed intrusions follow a familiar pattern of reconnaissance, lateral movement and persistence with web shells such as China Chopper. Patches are available in GeoServer 2.22.6, 2.23.6, 2.24.4 and 2.25.2, while a temporary mitigation involves removing the gt-complex jar file. Organizations are urged to apply updates immediately, restrict internet exposure and hunt for indicators of compromise in logs and on hosts.

BoletimSecVulnerabilities & Exploits

Microsoft Patches Seven Exchange Server Vulnerabilities Including Critical Remote Code Execution Flaw

Microsoft has addressed seven vulnerabilities in Exchange Server that enable remote code execution, privilege escalation, denial of service, content spoofing, and security feature bypass. The most severe issue, CVE-2026-62913, carries a CVSS score of 8.8 and involves a heap buffer overflow that can be exploited remotely by a low-privileged attacker without any user interaction. Successful exploitation grants code execution on the server, facilitating email theft, persistence mechanisms, lateral movement, and ransomware deployment. CVE-2026-62911, demonstrated at Pwn2Own Berlin with a CVSS score of 8.0, allows authentication bypass through capture and replay of credentials. Additional fixes cover SSRF-based privilege escalation, remote deserialization crashes, content spoofing, and authorization bypasses. Patches are available for Exchange Server Subscription Edition, while 2016 and 2019 versions receive updates only through the Extended Security Update program.

Security NEXTVulnerabilities & Exploits

Cisco Pre-Announces Security Advisories for Nine Product Families on August 19

Cisco Systems has issued an advance notice that it will publish security advisories for multiple products on August 19, 2026. The company released the pre-notification on August 12, confirming that nine distinct product groups will receive updates addressing security issues. No specific CVE identifiers, vulnerability descriptions, severity ratings, or affected versions were disclosed in the initial announcement. Cisco strongly recommends that customers apply the forthcoming fixes once they become available. The affected product families span collaboration, networking, contact center, and security platforms. Organizations using any of the listed solutions are advised to prepare for the upcoming patches and monitor Cisco’s official channels for detailed advisories.