Stack-based Buffer Overflow in Fortinet FortiWeb Products
CVE-2026-24640
5.9MEDIUM
What is CVE-2026-24640?
A stack-based buffer overflow vulnerability has been identified in various versions of Fortinet's FortiWeb products. This issue allows remote authenticated attackers to bypass stack protection mechanisms and address space layout randomization (ASLR). By sending specially crafted HTTP requests, attackers can execute arbitrary code or commands on the affected systems, potentially compromising their security and functionality.
Affected Version(s)
FortiWeb 8.0.0 <= 8.0.2
FortiWeb 7.6.0 <= 7.6.6
FortiWeb 7.4.0 <= 7.4.12