ZeroHour
Product

FortiManager Cloud

0 mentions in 7 days · 0 in 30 days · 1 total · first seen · last

Timeline

FGFM Authentication Weakening via CLI Configuration

FortiManager FGFM flaw (CVSS 7.3) lets an attacker with a valid certificate impersonate any managed FortiGate under a specific CLI option.

Fortinet advisory FG-IR-26-160 describes an authentication bypass via alternate path (CWE-288) in FortiManager and FortiManager Cloud, scored CVSSv3 7.3. A remote unauthenticated attacker holding a valid certificate can impersonate any FortiGate managed by the affected FortiManager when a specific CLI option is set. The impersonation is performed with crafted FGFM protocol requests. The advisory was revised on 2026-08-12 and does not report active exploitation.

Fortinet PSIRT · Aug 12, 2026Advisory

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.