CVE-2026-40688
published 2026-04-14CVE-2026-40688: An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through…
PriorityP357high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
6.44%
92.9th percentile
An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | >= 7.4.0 < 7.4.12 | 7.4.12 |
| fortinet | fortiweb | 7.4.0 – 7.4.11 | — |
| fortinet | fortiweb | >= 7.6.0 < 7.6.7 | 7.6.7 |
| fortinet | fortiweb | 7.6.0 – 7.6.6 | — |
| fortinet | fortiweb | >= 8.0.0 < 8.0.4 | 8.0.4 |
| fortinet | fortiweb | 8.0.0 – 8.0.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m3qh-6w2c-jgrx: A out-of-bounds write vulnerability in Fortinet FortiWeb 8
ghsa_unreviewed·2026-04-15
CVE-2026-40688 [HIGH] CWE-787 GHSA-m3qh-6w2c-jgrx: A out-of-bounds write vulnerability in Fortinet FortiWeb 8
A out-of-bounds write vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow attacker to execute unauthorized code or commands via
Fortinet
Out-Of-Bounds Write in administrative interface
vendor_fortinet·2026-04-14·CVSS 7.2
CVE-2026-40688 [HIGH] CWE-787 Out-Of-Bounds Write in administrative interface
FG-IR-26-127: Out-Of-Bounds Write in administrative interface
A out-of-bounds write vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow attacker to execute unauthorized code or commands via
CVEs: CVE-2026-40688
CWEs: CWE-787
CVSS: 7.2 (high)
Affected products: FortiWeb, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-14
Published