Fortinet Products Multiple Vulnerabilities
CSIRTS triage
- What
- Multiple vulnerabilities across Fortinet products of unknown type and impact.
- Who is affected
- Fortinet product users with affected versions.
- Urgency
- Severity and exploitability unknown; monitor vendor advisories for details.
- Action
- Check Fortinet security advisories to identify affected products and versions, then apply patches.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.hkcert.org/security-bulletin/fortinet-products-multiple-vulnerabilities_20260813
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-260350.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704650.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704660.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704680.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-714070.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-714080.56% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-26035 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70465 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70466 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70468 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71407 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71408 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0300 [1.00] [M/H] Vulnerabilities patched in Fortinet FortiWebncsc-nl
- unknownNCSC-2026-0299 [1.00] [M/H] Vulnerability patched in Fortinet FortiManagerncsc-nl
- unknownNCSC-2026-0296 [1.00] [M/H] Vulnerability patched in Fortinet FortiClientncsc-nl
- medium[NEW] [medium] Fortinet FortiOS: Multiple vulnerabilities enable code execution and DoScert-bund
- high[NEW] [high] Fortinet FortiManager: Vulnerability enables bypass of security measurescert-bund
- high[NEW] [high] Fortinet FortiWeb: Multiple vulnerabilities enable bypass of security measurescert-bund
- high[NEW] [high] Fortinet FortiClient: Vulnerability enables code executioncert-bund
- unknownMultiple vulnerabilities in Fortinet products (August 13, 2026)cert-fr-avis
- mediumCVE-2026-71408: A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0…nvd
- mediumCVE-2026-71407: A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 …nvd
- highCVE-2026-70468: A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiMana…nvd
- mediumCVE-2026-70466: A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2,…nvd
More from HKCERT Security Bulletins
- unknownMicrosoft Edge Multiple Vulnerabilities2026-08-17
- unknownVMWare Products Multiple Vulnerabilities2026-08-14
- unknownPalo Alto Products Multiple Vulnerabilities2026-08-14
- unknownMongoDB Multiple Vulnerabilities2026-08-13
- unknownIBM WebSphere Products Multiple Vulnerabilities2026-08-13