CVE-2026-24641: Null Pointer Dereference
A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24641?
CVE-2026-24641 is classified as a high severity vulnerability due to its potential to allow an authenticated attacker to crash the HTTP daemon.
How do I fix CVE-2026-24641?
To fix CVE-2026-24641, upgrade Fortinet FortiWeb to version 8.0.3 or later, or to version 7.6.7 or later.
Who is affected by CVE-2026-24641?
CVE-2026-24641 affects users of Fortinet FortiWeb versions 8.0.0 to 8.0.2, 7.6.0 to 7.6.6, and all versions of 7.4, 7.2, and 7.0.
What type of vulnerability is CVE-2026-24641?
CVE-2026-24641 is a NULL Pointer Dereference vulnerability, categorized under CWE-476.
What could an attacker achieve by exploiting CVE-2026-24641?
By exploiting CVE-2026-24641, an authenticated attacker could potentially crash the HTTP daemon, leading to service disruptions.