CVE-2026-70468: Fortinet FortiManager
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>
Affected products
- Fortinet FortiManager: from 7.2.5, before 7.2.10 (fixed in 7.2.10); from 7.4.3, before 7.4.6 (fixed in 7.4.6); version 7.6.1 only
- Fortinet FortiManager Cloud: from 7.2.5, before 7.2.10 (fixed in 7.2.10); from 7.4.3, up to and including 7.4.6; version 7.6.1 only
Published 2026-08-12. Last modified 2026-09-08.