NULL Pointer Dereference in Fortinet FortiOS and FortiPAM Products
CVE-2026-84392
2.5LOW
What is CVE-2026-84392?
A NULL Pointer Dereference vulnerability exists in Fortinet's FortiOS, FortiPAM, and FortiProxy products, which could allow an authenticated attacker to exploit the system via crafted HTTP requests. This could lead to the crashing of the httpsd daemon, resulting in potential service denial. All versions of the affected products are vulnerable, emphasizing the importance of prompt updates and configuration reviews to mitigate the risk of such exploitation.
Affected Version(s)
FortiOS 7.4.0 <= 7.4.12
FortiOS 7.2.0 <= 7.2.13
FortiOS 7.0.0 <= 7.0.19