Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 2 advisories

CVE-2026-70468

CVE-2026-70468: 2 tracked advisory records across Fortinet. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Fortinet

2 advisories
  • Advisory severityHigh7.3

    High [CVE-2026-70468] authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>

    CVE-2026-70468Source published Source updated

    A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control

    Affected products in this advisory
    • FortiManager Cloud
    Source-reported affected versions
    • FortiManager FortiManager: 7.2 through 7.6 (vendor-listed versions)
    • FortiManager Cloud FortiManager Cloud: 7.2 through 7.6 (vendor-listed versions)
    Source-reported fixed versions
    • FortiManager 7.6: 7.6.2
    • FortiManager 7.4: 7.4.6
    • FortiManager 7.2: 7.2.10
    • FortiManager Cloud 7.6: 7.6.2

    2 more entries in the full advisory.

    Mitigation guidance
    • Upgrade per the Affected/Solution table: FortiManager 7.6: 7.6.2; FortiManager 7.4: 7.4.6; FortiManager 7.2: 7.2.10; FortiManager Cloud 7.6: 7.6.2; FortiManager Cloud 7.4: 7.4.6; ….
    Workarounds
    • fgfm-peercert-withoutsn should be disabled :config system global set fgfm-peercert-withoutsn disableend
  • Advisory severityHigh7.3

    High [CVE-2026-70468] FGFM Authentication Weakening via CLI Configuration

    FG-IR-26-160Source published Source updated

    CVSSv3 Score: 7.3 An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate. Revised on 2026-08-12 00:00:00

    Affected products in this advisory
    • FortiManager Cloud
    Source-reported affected versions
    • FortiManager FortiManager: 7.2 through 7.6 (vendor-listed versions)
    • FortiManager Cloud FortiManager Cloud: 7.2 through 7.6 (vendor-listed versions)
    Source-reported fixed versions
    • FortiManager 7.6: 7.6.2
    • FortiManager 7.4: 7.4.6
    • FortiManager 7.2: 7.2.10
    • FortiManager Cloud 7.6: 7.6.2

    2 more entries in the full advisory.

    Mitigation guidance
    • Upgrade per the Affected/Solution table: FortiManager 7.6: 7.6.2; FortiManager 7.4: 7.4.6; FortiManager 7.2: 7.2.10; FortiManager Cloud 7.6: 7.6.2; FortiManager Cloud 7.4: 7.4.6; ….
    Workarounds
    • fgfm-peercert-withoutsn should be disabled :config system global set fgfm-peercert-withoutsn disableend

Android app · Google Play

Monitor future Fortinet CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery