cbcvebase.
CVE-2026-30897
published 2026-03-10

CVE-2026-30897: A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2…

PriorityP344medium6.6CVSS 3.1
AVNACHPRHUINSUCHIHAH
EPSS
0.63%
46.0th percentile
A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.

Affected

10 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortiweb
fortinetfortiweb>= 7.0.0 < 7.4.127.4.12
fortinetfortiweb7.0.0 – 7.0.12
fortinetfortiweb7.2.0 – 7.2.12
fortinetfortiweb7.4.0 – 7.4.11
fortinetfortiweb>= 7.6.0 < 7.6.77.6.7
fortinetfortiweb7.6.0 – 7.6.6
fortinetfortiweb>= 8.0.0 < 8.0.48.0.4
fortinetfortiweb8.0.0 – 8.0.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.