Content-Encoding WAF Evasion
FG-IR-26-157
CVSSv3 Score: 8.8 An Improper Authentication vulnerability [CWE-287] in the FortiWeb Remote Radius Type Admin Authentication configured with specific, non-default settings may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password Revised on 2026-08-12 00:00:00
The publication date reported by the vendor.
We collected the advisory from the official source.
Our collector saw this advisory during a later source check.