Fortinet Fixes Critical Login Flaws in FortiWeb and FortiManager
Fortinet has released patches for serious authentication flaws in two of its widely used security products, FortiWeb and FortiManager. According to the vendor, the vulnerabilities could allow attackers to log in using random or fabricated usernames and passwords, effectively bypassing normal authentication checks. A separate issue could let an attacker impersonate any FortiGate appliance, potentially undermining trust between devices in a Fortinet-managed network.
These products are commonly used by businesses to protect web applications and manage security infrastructure, meaning a successful exploit could give attackers a foothold to access sensitive systems or disrupt network defences entirely. Because authentication bypass flaws remove the usual barrier to unauthorized access, they are considered high-priority security issues that vendors and customers alike need to address quickly.
Australian small businesses using FortiWeb or FortiManager, whether managed in-house or through an IT provider, should treat this as an urgent update. Delays in patching authentication vulnerabilities significantly increase the window of opportunity for attackers scanning for exposed systems.