AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-71407

MEDIUM · CVSS 5.6 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Fortinet FortiOS versions 7.6.1 to 7.6.6 are susceptible to a stack-based buffer overflow vulnerability that could allow unauthenticated attackers to execute arbitrary code within the WAD daemon, provided that the explicit proxy is configured with Kerberos authentication and SOCKS is enabled. This vulnerability poses a medium risk, particularly for organizations utilizing FortiOS in environments where these configurations are in place. Security teams managing Fortinet products should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-71407
Severity
MEDIUM
CVSS
5.6
EPSS
0.49%
Fortinet FortiOS

Original NVD Description

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.