← All Advisories

Fortinet FortiWeb Out-of-Bounds Write Scores 7.2

Last refreshed2026-09-26

Status: EPSS-IMMINENT  |  Advisory ID: CVE-2026-40688

Key Details

CVECVE-2026-40688
CVSS Score / Version7.2 (High) / CVSS v3.1
Updated2026-09-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsFortinet FortiWeb
Classified asCWE-787 (Out-of-bounds Write)
Exploitation prediction (EPSS)0.88% probability of exploitation in the next 30 days (57% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
FortinetFortiWeb
SubsystemsGeneral OT
SectorsMulti-sector

What to Know

An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.

What to Do

Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-40688
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-40688
Vendor advisoryhttps://fortiguard.fortinet.com/psirt/FG-IR-26-127