CVE-2026-71408
published 2026-08-12CVE-2026-71408: A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.56%
44.0th percentile
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | 6.4.0 – 6.4.16 | — |
| fortinet | fortios | 7.0.0 – 7.0.19 | — |
| fortinet | fortios | 7.2.0 – 7.2.13 | — |
| fortinet | fortios | 7.4.0 – 7.4.12 | — |
| fortinet | fortios | 7.6.0 – 7.6.6 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service
ghsa_unreviewed·2026-08-12
CVE-2026-71408 [MEDIUM] CWE-770 A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via
Fortinet
UI DoS attack
vendor_fortinet·2026-08-12·CVSS 5.3
CVE-2026-71408 [MEDIUM] CWE-770 UI DoS attack
FG-IR-26-162: UI DoS attack
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via
CVEs: CVE-2026-71408
CWEs: CWE-770
CVSS: 5.3 (medium)
Affected products: FortiOS, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-12
Published