CVE-2026-59837

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, Forti

Severity
Medium 5.9
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.007
50.3th percentile
Discovered by
Third party
Vendor advisory field
Published
Jul 14, 2026
Assigned by fortinet

Description

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.

Weakness: CWE-121

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Check your version Firewall / NGFW cna-assigner
Fortinet FortiPAM Identity / IAM / MFA cna-assigner
Fortinet FortiProxy Check your version SASE / SSE / Secure Web cna-assigner
Fortinet FortiSASE SASE / SSE / Secure Web cna-assigner
Vendor-reported products (5)
  • Fortinet · FortiPAM
  • Fortinet · FortiSASE
  • Fortinet · FortiProxy
  • Fortinet · FortiOS
  • Siemens · RUGGEDCOM APE1808

Credit

Fortinet is pleased to thank Vang3lis and Cyth from VARAS@IIE for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.0 or above Upgrade to FortiOS version 7.4.2 or above Upgrade to FortiPAM version 1.9.0 or above Upgrade to FortiPAM version 1.8.3 or above Upgrade to FortiProxy version 7.6.0 or above Upgrade to FortiProxy version 7.4.14 or above

Something wrong here?