CVE-2026-24641

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb

Severity
Low 2.5
CVSS 3.1
Exploited
Not listed
EPSS
0.004
32.6th percentile
Discovered by
Third party
Vendor advisory field
Published
Mar 10, 2026
Assigned by fortinet

Description

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requests.

Weakness: CWE-476

Affected products

Vendor Product Category Matched by
Fortinet FortiWeb Web & Application Security cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiWeb

Credit

Fortinet is pleased to thank Sina Kheirkhah (SinSinology) of watchTowr (watchTowrcyber) for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to FortiWeb version 8.0.3 or above Upgrade to FortiWeb version 7.6.7 or above

Something wrong here?