FortinetCVE-2026-71407
Fortinet FortiOS: stack buffer overflow
Medium5.6CVE-2026-71407 · Published Aug 12, 2026 · updated Sep 8, 2026
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| FortiOS Product | >= 7.6.1, <= 7.6.6 | No fix yet |
| FortiPAM Product | >= 1.8.0, <= 1.8.4 | No fix yet |
| >= 1.7.0, <= 1.7.2 | No fix yet | |
| >= 1.6.0, <= 1.6.2 | No fix yet | |
| >= 1.5.0, <= 1.5.1 | No fix yet | |
| FortiProxy Product | >= 7.6.0, <= 7.6.4 | No fix yet |
| >= 7.4.0, <= 7.4.11 | No fix yet | |
| >= 7.2.0, <= 7.2.16 | No fix yet | |
| >= 7.0.0, <= 7.0.23 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-121
More Fortinet advisories
All Fortinet| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | Fortinet FortiSIEM: server-side request forgery | Low3.8 | No fix yet |
| Aug 12 | Fortinet FortiManager: authentication bypass | High8.1 | No fix yet |
| Aug 12 | Fortinet FortiOS: denial of service | Medium5.3 | No fix yet |
| Aug 12 | Fortinet FortiWeb: improper access control | Medium5.3 | No fix yet |
| Aug 12 | Fortinet FortiWeb: improper authentication | Critical9.8 | No fix yet |
| Aug 12 | Fortinet FortiClientWindows: buffer overflow | High8.1 | No fix yet |