CVE-2026-71408

A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service

Severity
Medium 5
CVSS 3.1
Exploited
Not listed
EPSS
0.006
44.0th percentile
Discovered by
Third party
Vendor advisory field
Published
Aug 12, 2026
Assigned by fortinet

Description

A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack vector here>

Weakness: CWE-770

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiOS

Credit

Fortinet is pleased to thank Iván Domínguez from Zerolynx for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.7 or above Upgrade to upcoming FortiAuthenticator version 8.0.4 or above

Something wrong here?