ZDI-CAN-28660: ZDI-26-265: Fortinet FortiWeb cgi_buf_alloc Integer Overflow Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Fortinet FortiWeb. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-39811.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28660?
The severity of ZDI-CAN-28660 is categorized as a denial-of-service vulnerability affecting Fortinet FortiWeb.
How do I fix ZDI-CAN-28660?
To fix ZDI-CAN-28660, ensure that your Fortinet FortiWeb installations are updated to the latest patched version provided by Fortinet.
Who is affected by ZDI-CAN-28660?
ZDI-CAN-28660 affects installations of Fortinet FortiWeb that require authentication for exploitation.
Can ZDI-CAN-28660 be exploited remotely?
Yes, ZDI-CAN-28660 can be exploited remotely, but authentication is required to carry out the attack.
What type of vulnerability is ZDI-CAN-28660?
ZDI-CAN-28660 is classified as an integer overflow vulnerability leading to denial-of-service conditions.