What is happening
Fortinet’s FortiManager line remains a high-value target in 2026 because it centralizes control over many security devices, and recent advisories continue to show authentication and code-execution risk in the platform. One of the most relevant issues in the current window is CVE-2026-22572, which affects FortiManager, FortiManager Cloud, FortiAnalyzer Cloud, and FortiAnalyzer, and can allow authentication bypass in certain configurations. Earlier Fortinet advisory coverage in April also showed multiple product issues, including FortiManager Cloud fixes that were still relevant for organizations running cloud-managed deployments.
Why this matters now
A FortiManager compromise is especially dangerous because the product can push configuration and policy changes across multiple Fortinet devices at once. That means one successful exploit can turn into broad downstream impact on firewalls, logging platforms, and managed gateways. Even when an issue is framed as MFA bypass or authentication bypass rather than direct code execution, the operational outcome can still be full administrative takeover.
Other active risk
Fortinet FortiManager has a history of severe exposure, including the widely exploited CVE-2024-47575 and later advisory follow-up from CERT-EU and national cybersecurity agencies. That history matters because it shows attackers already pay close attention to Fortinet management planes and will likely keep doing so whenever a new bypass or execution path appears. In 2026, the product family is still seeing fresh advisories, which makes it a live threat rather than a legacy concern.
Practical takeaway
If your organization uses FortiManager, confirm which branch you are on and whether it is affected by CVE-2026-22572 or earlier Fortinet management-plane vulnerabilities. Prioritize exposure reduction by limiting admin access, checking whether remote management is reachable from untrusted networks, and reviewing logs for suspicious authentication behavior. Because FortiManager can control many devices, patching it should be treated as infrastructure-critical, not just another appliance update.
CYBERSHIELDZONE