FORTINET Security Advisory

Published Date: February 10, 2026 (Updated July 4, 2026)

Advisory Summary

🔔 Critical Security Alert: LDAP Authentication Bypass in FortiOS Agentless VPN and FSSO

Fortinet has disclosed a significant vulnerability affecting FortiOS fnbamd component, identified under CVSSv3 score 7.5. This authentication bypass vulnerability (CWE-305) can be exploited when specific LDAP server configurations are in place, potentially allowing unauthenticated attackers to circumvent LDAP authentication mechanisms for Agentless VPN and Fortinet Single Sign-On (FSSO) policies.

This weakness poses a substantial risk to enterprises relying on Fortinet’s VPN and single sign-on security layers, as it undermines user authentication integrity, granting unauthorized network access. It is imperative for security teams and infrastructure administrators to review their LDAP server configurations and apply the recommended patches or mitigations promptly to prevent exploitation.

Stay vigilant and prioritize immediate assessment and remediation to safeguard critical VPN and identity management services.

Reference: Vendor Advisory