NCSC-2026-0299 [1.00] [M/H] Vulnerability patched in Fortinet FortiManager
Fortinet has patched a vulnerability in FortiManager and FortiManager Cloud versions 7.2.5 through 7.6.1. The vulnerability concerns an authentication bypass via an alternative route or channel. An external, unauthenticated attacker possessing a valid certificate can impersonate a FortiGate device managed by FortiManager by sending specially crafted FGFM requests. The cause lies in improper access control mechanisms within the affected versions, which may enable unauthorized access to managed devices.
CSIRTS triage
- What
- Authentication bypass via alternative channel allows external unauthenticated attackers with a valid certificate to impersonate FortiGate devices by sending specially crafted FGFM requests.
- Who is affected
- FortiManager and FortiManager Cloud deployments running versions 7.2.5 through 7.6.1.
- Urgency
- High urgency; attackers can impersonate managed devices and gain unauthorized access to the management infrastructure.
- Action
- Apply Fortinet's patch for CVE-2026-70468 to FortiManager and FortiManager Cloud systems.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiManager
Get an email when a new FortiManager advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0299
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-704680.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-70468 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Fortinet FortiManager: Vulnerability enables bypass of security measurescert-bund
- unknownFortinet Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Fortinet products (August 13, 2026)cert-fr-avis
- highCVE-2026-70468: A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiMana…nvd
- unknownFGFM Authentication Weakening via CLI Configurationfortinet
Recent advisories for Fortinet FortiManager
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Fortinet FortiManager: Vulnerability enables bypass of security measurescert-bund · 2026-08-13
- highCVE-2026-70468: A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiMana…nvd · 2026-08-12
- unknown[Update] Multiple vulnerabilities in Fortinet FortiManager (October 23, 2024)cert-fr-alerte · 2024-10-23
- criticalexploitedCVE-2024-47575: Fortinet FortiManager Missing Authentication Vulnerabilitycisa-kev · 2024-10-23
More from NCSC-NL Advisories
- unknownNCSC-2026-0302 [1.00] [M/H] Vulnerabilities patched in SAP Commerce Cloud Data Hub Adapter2026-08-15
- unknownNCSC-2026-0301 [1.00] [M/H] Vulnerabilities patched in IBM i operating system by IBM2026-08-14
- unknownNCSC-2026-0300 [1.00] [M/H] Vulnerabilities patched in Fortinet FortiWeb2026-08-13
- unknownNCSC-2026-0298 [1.00] [M/H] Vulnerabilities patched in Autodesk AutoCAD2026-08-13
- unknownNCSC-2026-0297 [1.00] [M/H] Vulnerabilities patched in GitLab Enterprise Edition and Community Edition2026-08-13