Executive brief
Fortinet FortiOS and related security appliances contain a heap-based buffer overflow vulnerability in packet processing that allows remote attackers to execute arbitrary code. Exploitation has been observed in the wild, making this an active threat to organizations relying on these products for network security and management.
Technical details
A heap-based buffer overflow exists in the packet processing functionality of Fortinet FortiOS, FortiSwitchManager, and FortiSASE. The vulnerability is triggered when the affected products process specially crafted network packets, leading to memory corruption on the heap. An unauthenticated remote attacker on the network can exploit this vulnerability without user interaction to achieve arbitrary code execution with the privileges of the vulnerable process. The vulnerability is being actively exploited in the wild, indicating broad availability of exploit code or techniques.
Affected products
- Fortinet FortiOS
- Fortinet FortiSwitchManager
- Fortinet FortiSASE
Timeline
- 2026-09-09: disclosed
- exploited: Active exploitation reported in the wild