← All Advisories

Fortinet FortiManager and FortiAnalyzer Cloud Heap Overflow Scores 8.1

Last refreshed2026-09-26

Status: UPDATED  |  Advisory ID: CVE-2026-22828

Key Details

CVECVE-2026-22828
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsFortinet FortiManager Cloud and Fortinet FortiAnalyzer Cloud
Classified asCWE-122 (Heap-based Buffer Overflow)
Exploitation prediction (EPSS)0.90% probability of exploitation in the next 30 days (58% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
FortinetFortiManager Cloud
FortinetFortiAnalyzer Cloud
SubsystemsGeneral OT
SectorsMulti-sector

What to Know

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation

What to Do

Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-22828
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-22828
Vendor advisoryhttps://fortiguard.fortinet.com/psirt/FG-IR-26-121