cbcvebase.
CVE-2026-24640
published 2026-03-10

CVE-2026-24640: A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all…

PriorityP345medium6.6CVSS 3.1
AVNACHPRHUINSUCHIHAH
EPSS
0.63%
46.0th percentile
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0.2 through 7.0.12 may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.

Affected

9 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortiweb
fortinetfortiweb7.0.2 – 7.0.12
fortinetfortiweb>= 7.2.0 < 7.6.77.6.7
fortinetfortiweb7.2.0 – 7.2.12
fortinetfortiweb7.4.0 – 7.4.12
fortinetfortiweb7.6.0 – 7.6.6
fortinetfortiweb>= 8.0.0 < 8.0.38.0.3
fortinetfortiweb8.0.0 – 8.0.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.