
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24640 is a Stack-based Buffer Overflow vulnerability (CWE-121) in Fortinet FortiWeb's API protection component that may allow a remote authenticated attacker to execute arbitrary code or commands via crafted HTTP requests. Affected versions include FortiWeb 8.0.0–8.0.2, 7.6.0–7.6.6, 7.4 (all versions), 7.2 (all versions), and 7.0.2–7.0.12. The vulnerability was publicly disclosed on March 10, 2026, and was reported by Sina Kheirkhah (SinSinology) of watchTowr under responsible disclosure. It carries a CVSS v3.1 base score of 6.6 (Medium) per NVD, or 5.9 (Medium) per Fortinet's own advisory (Fortinet PSIRT, Feedly).
The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow) and CWE-787 (Out-of-bounds Write), residing in the API protection component of FortiWeb. An attacker can trigger the overflow by sending specially crafted HTTP requests to the affected system, but successful exploitation requires the attacker to first bypass stack protection mechanisms and ASLR (Address Space Layout Randomization), significantly raising the exploitation bar. The attack vector is network-based, requires high privileges (authenticated access), and has high attack complexity due to the memory protection bypass requirement. No public proof-of-concept exploit code has been identified as of the time of disclosure (Fortinet PSIRT, Feedly).
Successful exploitation could allow a remote authenticated attacker to execute arbitrary code or commands on the affected FortiWeb system, potentially resulting in complete compromise of the web application firewall. This could lead to full confidentiality, integrity, and availability impact — including data theft, unauthorized configuration changes, service disruption, and potential lateral movement to other systems protected or managed by the FortiWeb instance (Fortinet PSIRT, Feedly).
As of the disclosure date, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation. Fortinet's advisory confirms the vulnerability has not been exploited in the wild ("Known Exploited: No"). The EPSS score is approximately 0.053%, reflecting a low near-term exploitation probability. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The high attack complexity — specifically the requirement to bypass both stack canaries and ASLR — substantially limits the practical exploitability of this vulnerability (Fortinet PSIRT, Feedly).
Fortinet has released patched versions to address this vulnerability. Organizations should upgrade to the following fixed releases: FortiWeb 8.0.3 or above (for 8.0.x users), FortiWeb 7.6.7 or above (for 7.6.x users). Users on FortiWeb 7.4, 7.2, or 7.0.x should migrate to a fixed release, as no in-branch patch is available for those versions. As interim mitigations, organizations should restrict administrative access to FortiWeb to only authorized users, limit network exposure of the management interface, and monitor for suspicious HTTP requests and unusual process activity on FortiWeb systems (Fortinet PSIRT).
The vulnerability was discovered and responsibly disclosed by Sina Kheirkhah (SinSinology) of watchTowr, a well-regarded offensive security research firm known for identifying vulnerabilities in network security appliances. Fortinet acknowledged the researcher's contribution in their official advisory. No significant broader media coverage or notable community debate has been identified beyond standard vulnerability tracking and aggregation (Fortinet PSIRT).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."