VYPR
patchPublished Aug 12, 2026· 1 source

FortiOS Explicit Proxy Vulnerable to Stack Buffer Overflow

A critical stack buffer overflow vulnerability in FortiOS's explicit proxy WAD daemon could allow unauthenticated attackers to execute arbitrary code.

Fortinet has disclosed a critical stack-based buffer overflow vulnerability (CWE-121) affecting its FortiOS explicit proxy feature. The vulnerability resides within the WAD daemon and, if successfully exploited, could permit an unauthenticated attacker to achieve arbitrary code execution.

The exploit mechanism involves bypassing standard stack protection and Address Space Layout Randomization (ASLR) through the use of specially crafted network sockets. This sophisticated attack vector requires the explicit proxy to be configured with specific settings: Kerberos authentication must be enabled, and the SOCKS proxy must also be active. These prerequisites significantly narrow the potential attack surface, but the severity of arbitrary code execution remains a major concern for affected organizations.

FortiOS versions 7.6.1 through 7.6.6 are confirmed to be vulnerable. Fortinet has released patches, recommending an upgrade to FortiOS 7.6.7 or a later version to remediate the issue. Other versions, including 8.0, 7.4, and 7.2, are not affected by this particular vulnerability.

As a mitigation strategy, organizations can disable the SOCKS proxy feature by executing the command config web-proxy explicit set socks disable. Alternatively, administrators can modify the authentication scheme for the SOCKS proxy to avoid using Kerberos authentication. These workarounds can provide immediate protection while patching is being implemented.

A virtual patch, identified as "FG-VD-10009617.0day," is also available through FortiManager Web Protection (FMWP) database update 26.073, offering an additional layer of defense.

The vulnerability was responsibly disclosed by The UK's National Cyber Security Centre (NCSC). Fortinet has published the initial advisory on August 12, 2026, marking the public disclosure of this security flaw.

This vulnerability underscores the ongoing challenges in securing network edge devices and proxy services, especially when complex authentication and proxy configurations are in place. The ability to bypass security mechanisms like ASLR and stack protection highlights the need for continuous vigilance and prompt patching of critical infrastructure.

Synthesized by Vypr AI