CVE-2026-59837
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, Forti
Description
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.
Weakness: CWE-121
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
| Fortinet | FortiPAM | Identity / IAM / MFA | cna-assigner |
| Fortinet | FortiProxy | SASE / SSE / Secure Web | cna-assigner |
| Fortinet | FortiSASE | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (4)
- Fortinet · FortiPAM
- Fortinet · FortiSASE
- Fortinet · FortiProxy
- Fortinet · FortiOS
Vendor remediation
Upgrade to FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.0 or above Upgrade to FortiOS version 7.4.2 or above Upgrade to FortiPAM version 1.9.0 or above Upgrade to FortiPAM version 1.8.3 or above Upgrade to FortiProxy version 7.6.0 or above Upgrade to FortiProxy version 7.4.14 or above