CVE-2026-24640: Buffer Overflow
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0.2 through 7.0.12 may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24640?
CVE-2026-24640 is considered a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-24640?
To fix CVE-2026-24640, update Fortinet FortiWeb to version 8.0.3 or later, or to any version beyond 7.6.6 if it falls under that version range.
Who is affected by CVE-2026-24640?
CVE-2026-24640 affects Fortinet FortiWeb versions 8.0.0 through 8.0.2, 7.6.0 through 7.6.6, and several other specified versions.
What type of vulnerability is CVE-2026-24640?
CVE-2026-24640 is a stack-based buffer overflow vulnerability, which is a common type of programming error that can lead to security exploits.
Can CVE-2026-24640 be exploited remotely?
Yes, CVE-2026-24640 can be exploited by a remote authenticated attacker who can bypass stack protection.