Stack-based Buffer Overflow in Fortinet FortiOS Products
CVE-2026-71407

5.1MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
12 August 2026

What is CVE-2026-71407?

A stack-based buffer overflow vulnerability exists in Fortinet's FortiOS versions 7.6.1 to 7.6.6. This flaw allows unauthenticated attackers to potentially execute arbitrary code or commands within the context of the WAD daemon. The vulnerability is exploitable only when the explicit proxy is configured with Kerberos authentication and SOCKS is enabled. Attackers can leverage crafted sockets to bypass stack protection and address space layout randomization (ASLR), posing a significant security risk.

Affected Version(s)

FortiOS 7.6.1 <= 7.6.6

FortiPAM 1.8.0 <= 1.8.4

FortiPAM 1.7.0 <= 1.7.2

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.