CVE-2026-59837

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, Forti

Severity
Medium 5.9
CVSS 3.1
Exploited
Not listed
EPSS
0.006
44.3th percentile
Discovered by
Not disclosed
Published
Jul 14, 2026
Assigned by fortinet

Description

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.

Weakness: CWE-121

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Fortinet FortiPAM Identity / IAM / MFA cna-assigner
Fortinet FortiProxy SASE / SSE / Secure Web cna-assigner
Fortinet FortiSASE SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (4)
  • Fortinet · FortiPAM
  • Fortinet · FortiSASE
  • Fortinet · FortiProxy
  • Fortinet · FortiOS

Vendor remediation

Upgrade to FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.0 or above Upgrade to FortiOS version 7.4.2 or above Upgrade to FortiPAM version 1.9.0 or above Upgrade to FortiPAM version 1.8.3 or above Upgrade to FortiProxy version 7.6.0 or above Upgrade to FortiProxy version 7.4.14 or above