SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-59837

MEDIUM · CVSS 6.6 EPSS 0.71%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Fortinet FortiOS and FortiPAM versions are vulnerable to a stack-based buffer overflow that allows a privileged authenticated attacker to execute arbitrary code or commands by sending specially crafted HTTP requests. This vulnerability poses a medium severity risk, particularly for organizations using affected versions of FortiOS and FortiPAM, as it could lead to unauthorized access and control over the system. Security teams managing these products should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-59837
Severity
MEDIUM
CVSS
6.6
EPSS
0.71%
Fortinet FortiOS

Original NVD Description

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.

Related CVEs

Other vulnerabilities affecting the same vendor(s)