CVE-2026-39811
published 2026-04-14CVE-2026-39811: A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2…
PriorityP424medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
0.37%
28.7th percentile
A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to denial of service via
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | 7.0.0 – 7.0.13 | — |
| fortinet | fortiweb | 7.2.0 – 7.2.13 | — |
| fortinet | fortiweb | 7.4.0 – 7.4.12 | — |
| fortinet | fortiweb | >= 7.6.0 < 7.6.7 | 7.6.7 |
| fortinet | fortiweb | 7.6.0 – 7.6.6 | — |
| fortinet | fortiweb | >= 8.0.0 < 8.0.4 | 8.0.4 |
| fortinet | fortiweb | 8.0.0 – 8.0.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vf2h-7fg9-fhfj: A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8
ghsa_unreviewed·2026-04-14
CVE-2026-39811 [MEDIUM] CWE-190 GHSA-vf2h-7fg9-fhfj: A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8
A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to denial of service via
Fortinet
Integer Overflow Denial of Service in administrative interface
vendor_fortinet·2026-04-14·CVSS 4.9
CVE-2026-39811 [MEDIUM] CWE-190 Integer Overflow Denial of Service in administrative interface
FG-IR-26-108: Integer Overflow Denial of Service in administrative interface
A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to denial of service via
CVEs: CVE-2026-39811
CWEs: CWE-190
CVSS: 4.9 (medium)
Affected products: FortiWeb, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-14
Published