Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5073 articles · 189137 vulns · 37/41 feeds (7d)
← Back to list
5.1
CVE-2026-71407
fortinet · fortios

CVE-2026-71407: A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an

Description

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.

Affected Products

VendorProductVersions
fortinetfortios7.6.1, 1.8.0, 1.7.0, 1.6.0, 1.5.0, 1.4.0, 1.3.0, 1.2.0, 1.1.0, 1.0.0, 7.6.0, 7.4.0, 7.2.0, 7.0.0

References

  • https://fortiguard.fortinet.com/psirt/FG-IR-26-161

Related News (2 articles)

Tier C
VulDB9h ago
CVE-2026-71407 | Fortinet FortiPAM/FortiProxy/FortiOS 7.6.1-7.6.6 WAD daemon stack-based overflow
→ No new info (linked only)
Tier A
Fortinet PSIRT15h ago
Stack buffer overflow in WAD
→ No new info (linked only)
CVSS 3.15.1 MEDIUM
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
CISA KEV❌ No
Actively exploited❌ No
CWECWE-121
PublishedAug 12, 2026
Trending Score38
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-26035
CVE-2026-26035: An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.
Trending: 52
MEDIUMCVE-2026-70466
CVE-2026-70466: A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.
Trending: 48
MEDIUMCVE-2026-71408
CVE-2026-71408: A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.
Trending: 43
HIGHCVE-2026-70465
CVE-2026-70465: A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.
Trending: 42
HIGHCVE-2026-70468
CVE-2026-70468: A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.
Trending: 42

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 12, 2026
Discovered by ZDM
Aug 12, 2026