CVE-2026-71408: UI DoS attack
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack vector here>
Other sources
An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web interface via crafted HTTP requests.
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiOSto a version that resolves this vulnerability.Fixed in 7.6.7 - Upgrade
Upgrade
Fortinet FortiOSto a version that resolves this vulnerability.Fixed in 8.0.0 - Upgrade
Upgrade
Fortinet FortiAuthenticatorto a version that resolves this vulnerability.Fixed in 8.0.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71408?
CVE-2026-71408 has a medium severity rating of 5.
How do I fix CVE-2026-71408?
To mitigate CVE-2026-71408, upgrade FortiOS to version 7.6.7 or later.
What kind of attack does CVE-2026-71408 enable?
CVE-2026-71408 allows for a denial of service (DoS) attack due to the allocation of resources without limits.
Which versions of FortiOS are affected by CVE-2026-71408?
CVE-2026-71408 affects FortiOS versions 7.6.0 through 7.6.6, as well as all versions of 7.4 and 7.2.
Is user interaction required to exploit CVE-2026-71408?
No, CVE-2026-71408 does not require user interaction to exploit.