Junglewise Threat Intelligence

CVE-2026-59837: Fortinet FortiOS and FortiPAM stack overflow in GUI

CVE-2026-59837 · Severity: medium · CVSS 6.6 · Published 2026-07-14

Technologies: Fortinet Fortipam, Fortinet FortiOS, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

A security vulnerability exists in several Fortinet products, including the FortiOS operating system and FortiPAM access management tool. A highly privileged user could potentially take full control of the device or execute unauthorized commands by sending specially crafted web requests. While the risk is mitigated by the requirement for administrative access and the need to bypass modern security protections, an exploit could lead to a total compromise of the affected security appliance.

Technical details

A stack-based buffer overflow vulnerability (CWE-121) exists in the GUI component of Fortinet FortiOS, FortiPAM, and FortiProxy. The flaw is triggered via specially crafted HTTP requests. Exploitation requires high privileges (PR:H) and is considered high complexity (AC:H) because an attacker must successfully bypass modern exploit mitigations, specifically stack protection (canaries) and Address Space Layout Randomization (ASLR). If successful, the attacker can achieve arbitrary code execution or command injection. Patches are available in FortiOS 7.4.2, FortiPAM 1.8.3, and FortiProxy 7.4.14; users on 7.2 branches are advised to migrate to fixed releases.

Affected products

  • Fortinet FortiOS 7.4.0 through 7.4.1, 7.2 all versions
  • Fortinet FortiPAM 1.0 through 1.8.2
  • Fortinet FortiProxy 7.4.0 through 7.4.13, 7.2 all versions

Timeline

  • 2026-07-14: advisory: Initial publication by Fortinet
  • 2026-07-14: disclosed

References

Related threats