CRITICALVulnerability
Verified
Global

Critical Fortinet FortiManager Flaw Enables Managed Firewall Takeover

Saturday, March 21, 2026 at 04:00 PM UTC·Source: Fortinet PSIRT / Mandiant

Updated: Sunday, March 22, 2026 at 12:00 PM UTC

Executive Summary

CVE-2026-48788 allows registration of rogue FortiGate devices to FortiManager, enabling config push to entire managed firewall estate.

Analysis

Unauthenticated attackers can register rogue FortiGate devices and push malicious configs to all managed firewalls. CVSS 9.8. Mandiant links exploitation to UNC3886 deploying firmware implants surviving factory resets. Patch immediately and audit device registrations.

Timeline

Discovered
Mar 10, 2026
Exploitation Detected
Mar 12, 2026
Published
Mar 21, 2026
Patch Available
Mar 21, 2026

Indicators of Compromise (1)

CVE (1)
CVE-2026-48788
Source Attribution

Originally published by Fortinet PSIRT / Mandiant on Mar 21, 2026. Verified by: CISA, Fortinet PSIRT, Mandiant.

Related Threats