Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3034 articles · 183090 vulns · 36/41 feeds (7d)
← Back to list
4.1
CVE-2026-59840
fortinet · fortios

CVE-2026-59840: A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v

Description

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to information disclosure via <insert attack vector here>

Affected Products

VendorProductVersions
fortinetfortios7.6.0, 7.4.0, 7.2.0, 7.0.0, 6.4.0, 1.7.0, 1.6.0, 1.5.0, 1.4.0, 1.3.0, 1.2.0, 1.1.0, 1.0.0, 7.2.0, 7.0.0, 7.6.0, 7.4.0, 7.2.0, 7.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
fortinetfortioscert_advisory90%
fortinetfortiproxycert_advisory90%

References

  • https://fortiguard.fortinet.com/psirt/FG-IR-26-154

Related News (3 articles)

Tier B
BSI Advisories17d ago
[NEU] [niedrig] Fortinet FortiProxy und FortiOS: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits Fortinet (15 juillet 2026)
→ No new info (linked only)
Tier C
VulDB18d ago
CVE-2026-59840 | Fortinet FortiOS/FortiPAM/FortiSwitchManager/FortiProxy buffer overflow
→ No new info (linked only)
CVSS 3.14.1 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
CISA KEV❌ No
Actively exploited❌ No
CWECWE-126
PublishedJul 14, 2026
Last enriched18d agov2
Trending Score5
Source articles3
Independent3
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-25089EXP
CVE-2026-25089: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
Trending: 83
HIGHCVE-2026-59835
CVE-2026-59835: A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 th
Trending: 9
MEDIUMCVE-2026-59837
CVE-2026-59837: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM
Trending: 7
MEDIUMCVE-2026-23573
CVE-2026-23573: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi
Trending: 6
MEDIUMCVE-2026-59839
CVE-2026-59839: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0
Trending: 6

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: description, severity
Jul 14, 2026

Version History

v2
Last enriched 18d ago
v2Tier C18d ago

Updated description with new technical details, added FortiPAM to products, and changed severity to HIGH.

descriptionseverity
via VulDB
v118d ago

Initial creation