CVE-2026-39811
A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions m
Severity
Medium 4.4
CVSS 3.1
Exploited
Not listed
EPSS
0.004
30.4th percentile
Discovered by
Third party
Vendor advisory field
Published
Apr 14, 2026
Assigned by fortinet
Description
A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to denial of service via <insert attack vector here>
Weakness: CWE-190
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiWeb | Web & Application Security | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiWeb
Credit
Fortinet is pleased to thank Jason McFadyen of TrendAI Research for reporting this vulnerability under responsible disclosure.
Vendor remediation
Upgrade to FortiWeb version 8.0.4 or above Upgrade to FortiWeb version 7.6.7 or above