VYPR
High severity7.2NVD Advisory· Published Apr 14, 2026· Updated Apr 20, 2026

CVE-2026-40688

CVE-2026-40688

Description

An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.

Affected products

1
  • cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
    Range: >=7.4.0,<7.4.12

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

1