B
今週中
Fortinetは、FortiWebおよびFortiManagerにおける認証不備を含む8つの脆弱性を修正しました
📌 一言でいうと
Fortinetは、FortiWebおよびFortiManagerにおける認証不備を含む8つの脆弱性を修正しました。特にFortiWebのCVE-2026-26035は、特定の非デフォルト設定(ワイルドカード設定)が有効な場合に、攻撃者が任意のユーザー名とパスワードでGUI/CLIにログインできる深刻な問題です。FortiManagerにおいても認証に関する脆弱性が報告されており、迅速なパッチ適用が推奨されています。
🔍該当判定
- FortiWeb(WAF)を導入しており、管理画面へのログインに「ワイルドカード設定(wildcard setting)」を有効にして利用している
- FortiWeb(WAF)を利用しており、管理者アカウントの認証に外部のリモートサーバー(LDAP/RADIUS等)を連携させている
- FortiManager(ネットワーク管理ツール)を導入して運用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
影響を受けるバージョンのFortiWebおよびFortiManagerを最新バージョンにアップデートすること。FortiWebにおいてアップデートが困難な場合は、暫定処置としてワイルドカード設定を無効化することを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】FortiWeb / FortiManager 認証脆弱性 (CVE-2026-26035 他) 対応について
お疲れさまです。Fortinet製品の脆弱性に関する情報共有です。
■ 概要
FortiWebおよびFortiManagerにおいて、認証をバイパスし管理権限を奪取される可能性がある脆弱性が公開されました。特にFortiWebのCVE-2026-26035は、ワイルドカード設定が有効な環境において、任意の認証情報でログインが可能です。
■ 影響範囲
- FortiWeb: 特定のバージョン(修正済み: 8.0.3, 7.6.7, 7.4.12, 7.2.13)
- FortiManager: CVE-2026-70468 の影響を受けるバージョン
■ 対応手順
1. 利用中の製品バージョンを確認し、最新の修正済みバージョンへアップデートを適用してください。
2. FortiWebにおいて即時のアップデートが困難な場合は、設定から「wildcard」設定を無効化してください。
■ 参考情報
- Fortinet公式アドバイザリ
対応優先度: 高
対応期限: 速やかに
お疲れさまです。Fortinet製品の脆弱性に関する情報共有です。
■ 概要
FortiWebおよびFortiManagerにおいて、認証をバイパスし管理権限を奪取される可能性がある脆弱性が公開されました。特にFortiWebのCVE-2026-26035は、ワイルドカード設定が有効な環境において、任意の認証情報でログインが可能です。
■ 影響範囲
- FortiWeb: 特定のバージョン(修正済み: 8.0.3, 7.6.7, 7.4.12, 7.2.13)
- FortiManager: CVE-2026-70468 の影響を受けるバージョン
■ 対応手順
1. 利用中の製品バージョンを確認し、最新の修正済みバージョンへアップデートを適用してください。
2. FortiWebにおいて即時のアップデートが困難な場合は、設定から「wildcard」設定を無効化してください。
■ 参考情報
- Fortinet公式アドバイザリ
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] FortiWeb and FortiManager Authentication Vulnerabilities (CVE-2026-26035 et al.)
Dear Team,
This is a notification regarding critical authentication vulnerabilities in Fortinet products.
■ Overview
Fortinet has patched vulnerabilities in FortiWeb and FortiManager. Specifically, CVE-2026-26035 in FortiWeb allows a remote, unauthenticated attacker to log into the GUI/CLI with random credentials if the non-default wildcard setting for administrator accounts is enabled.
■ Affected Scope
- FortiWeb: Versions prior to 8.0.3, 7.6.7, 7.4.12, and 7.2.13
- FortiManager: Versions affected by CVE-2026-70468
■ Mitigation Steps
1. Update FortiWeb and FortiManager to the latest patched versions immediately.
2. For FortiWeb, as a temporary workaround, disable the 'wildcard' setting for administrator accounts.
■ Reference
- Fortinet Official Security Advisory
Priority: High
Deadline: Immediate
Dear Team,
This is a notification regarding critical authentication vulnerabilities in Fortinet products.
■ Overview
Fortinet has patched vulnerabilities in FortiWeb and FortiManager. Specifically, CVE-2026-26035 in FortiWeb allows a remote, unauthenticated attacker to log into the GUI/CLI with random credentials if the non-default wildcard setting for administrator accounts is enabled.
■ Affected Scope
- FortiWeb: Versions prior to 8.0.3, 7.6.7, 7.4.12, and 7.2.13
- FortiManager: Versions affected by CVE-2026-70468
■ Mitigation Steps
1. Update FortiWeb and FortiManager to the latest patched versions immediately.
2. For FortiWeb, as a temporary workaround, disable the 'wildcard' setting for administrator accounts.
■ Reference
- Fortinet Official Security Advisory
Priority: High
Deadline: Immediate