Multiple vulnerabilities in Fortinet products (August 13, 2026)
Multiple vulnerabilities have been discovered in Fortinet products. Some of them allow an attacker to cause arbitrary remote code execution, privilege escalation and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities in Fortinet products allow remote code execution, privilege escalation, and denial of service.
- Who is affected
- Organizations deploying Fortinet products (specific products unspecified).
- Urgency
- High; remote code execution and privilege escalation are critical attack vectors.
- Action
- Identify affected Fortinet products and apply patches for the listed CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1015/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-714080.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-260350.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Elevated exploitation riskCVE-2026-4997531.0% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 98% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-714070.54% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704670.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704650.67% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704680.69% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704660.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-71408 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-26035 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-49975 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71407 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70467 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70465 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70468 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70466 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] Apache HTTP Server: Mehrere Schwachstellencert-bund
- high[UPDATE] [high] HTTP/2 implementations: Vulnerability allows denial of servicecert-bund
- unknownNCSC-2026-0300 [1.00] [M/H] Vulnerabilities patched in Fortinet FortiWebncsc-nl
- unknownNCSC-2026-0299 [1.00] [M/H] Vulnerability patched in Fortinet FortiManagerncsc-nl
- unknownNCSC-2026-0296 [1.00] [M/H] Vulnerability patched in Fortinet FortiClientncsc-nl
- low[NEW] [low] Fortinet FortiSIEM: Vulnerability enables data manipulationcert-bund
- medium[NEW] [medium] Fortinet FortiOS: Multiple vulnerabilities enable code execution and DoScert-bund
- high[NEW] [high] Fortinet FortiManager: Vulnerability enables bypass of security measurescert-bund
- high[NEW] [high] Fortinet FortiClient: Vulnerability enables code executioncert-bund
- high[NEW] [high] Fortinet FortiWeb: Multiple vulnerabilities enable bypass of security measurescert-bund
- unknownFortinet Products Multiple Vulnerabilitieshkcert
- mediumCVE-2026-71408: A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0…nvd
Recent advisories for Fortinet products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownFortinet Products Multiple Vulnerabilitieshkcert · 2026-09-09
- criticalexploitedCVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerabilitycisa-kev · 2026-09-09
- unknownFortinet Products Multiple Vulnerabilitieshkcert · 2026-08-13
- unknownNCSC-2026-0240 [1.00] [M/H] Vulnerabilities fixed in multiple Fortinet productsncsc-nl · 2026-07-15
- unknownMultiple vulnerabilities in Fortinet products (July 15, 2026)cert-fr-avis · 2026-07-15
- criticalexploitedCVE-2026-24858: Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerabil…cisa-kev · 2026-01-27
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans les produits Veeam (10 septembre 2026)2026-09-10
- unknownVulnérabilité dans Apereo CAS (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans HPE Aruba Networking ClearPass Policy Manager (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans les produits Check Point (10 septembre 2026)2026-09-10
- unknownVulnérabilité dans Laravel (10 septembre 2026)2026-09-10