
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40688 is an out-of-bounds write vulnerability (CWE-787) in the CGI daemon of Fortinet FortiWeb that may allow a remote privileged attacker to execute arbitrary code or commands via crafted HTTP requests. It affects FortiWeb versions 8.0.0–8.0.3, 7.6.0–7.6.6, and 7.4.0–7.4.11; versions 7.2 and 7.0 are not affected. The vulnerability was disclosed on April 15, 2026, and was reported by Jason McFadyen of TrendAI Research under responsible disclosure. It carries a CVSS v3.1 base score of 7.2 (High) per NVD/GitHub Advisory, while Fortinet's own advisory rates it 6.7 (Medium) (Fortinet PSIRT, GitHub Advisory).
The vulnerability is rooted in improper validation of user-supplied data within the FortiWeb CGI daemon, classified as CWE-787 (Out-of-bounds Write). An attacker can send specially crafted HTTP requests to the administrative interface, causing the daemon to write data beyond the bounds of an allocated buffer, which can lead to arbitrary code or command execution. Exploitation requires network access and high (administrative) privileges on the target system, meaning the attack surface is limited to authenticated sessions on the management interface. The Zero Day Initiative advisory (ZDI-26-266) corroborates that the issue stems from lack of proper validation of user-supplied data (Fortinet PSIRT, ZDI Advisory).
Successful exploitation allows a remote attacker with administrative privileges to execute arbitrary code or commands on the affected FortiWeb appliance, resulting in full compromise of confidentiality, integrity, and availability of the system. An attacker who achieves code execution on a FortiWeb instance — which functions as a web application firewall — could intercept, modify, or suppress web traffic it protects, potentially enabling lateral movement into backend application environments. Data exposure risk includes access to sensitive configuration, credentials, and proxied application traffic (Fortinet PSIRT, GitHub Advisory).
As of the time of disclosure, there is no confirmed in-the-wild exploitation or publicly available proof-of-concept exploit code. The ZDI advisory (ZDI-26-266) describes the vulnerability but does not provide exploitation steps or payloads, and Fortinet's advisory marks "Known Exploited: No." The EPSS score is approximately 0.12–0.18%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Fortinet PSIRT, ZDI Advisory, GitHub Advisory).
Fortinet has released patched versions addressing this vulnerability. Affected users should upgrade to the following fixed releases as soon as possible:
As a compensating control, restrict administrative access to the FortiWeb management interface to trusted IP addresses only, and monitor for suspicious or anomalous HTTP requests targeting the administrative interface. No configuration-based workaround is documented as a substitute for patching (Fortinet PSIRT).
Fortinet credited Jason McFadyen of TrendAI Research for responsible disclosure of this vulnerability. The Zero Day Initiative published advisory ZDI-26-266 covering the flaw, and Check Point also published a defense advisory (CPAI-2026-4584). Greenbone noted the vulnerability in a broader blog post covering Fortinet RCE vulnerabilities in 2026. Community reaction has been measured given the requirement for high privileges, with no significant alarm or widespread social media discussion observed (ZDI Advisory, Fortinet PSIRT).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."