
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59837 is a stack-based buffer overflow vulnerability (CWE-121) in Fortinet FortiOS, FortiProxy, and FortiPAM that may allow a privileged authenticated attacker to execute arbitrary code or commands via crafted HTTP requests. Affected versions include FortiOS 7.4.0–7.4.1 and 7.2 all versions, FortiProxy 7.4.0–7.4.13 and 7.2 all versions, and FortiPAM 1.0 through 1.8.2. FortiSASE 26.1.1–26.1.2 is also listed as affected. The vulnerability was publicly disclosed on July 14, 2026, with a CVSS v3.1 base score of 6.6 (Medium/High) per NVD and 5.9 (Medium) per Fortinet's advisory (FortiGuard Advisory, Feedly).
The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow) and resides in the GUI component of the affected Fortinet products. An attacker can exploit this flaw by sending crafted HTTP requests that overflow a stack buffer, potentially enabling arbitrary code or command execution. Exploitation requires the attacker to be a privileged authenticated user and to additionally bypass stack protection mechanisms (stack canaries) and Address Space Layout Randomization (ASLR), significantly raising the attack complexity. The vulnerability was discovered externally and reported by Vang3lis and Cyth from VARAS@IIE under responsible disclosure (FortiGuard Advisory).
Successful exploitation allows a privileged authenticated attacker to execute arbitrary code or commands on the affected system, resulting in full compromise of confidentiality, integrity, and availability. Given that FortiOS, FortiProxy, and FortiPAM are commonly deployed as network security and privileged access management infrastructure, a compromised device could serve as a pivot point for lateral movement into protected network segments or privileged account stores. The technical impact is rated as "total" by NVD's SSVC assessment (FortiGuard Advisory, Feedly).
Fortinet has released patched versions: FortiOS 7.4.2 or above (FortiOS 7.2 users must migrate to a fixed release), FortiProxy 7.4.14 or above (FortiProxy 7.2 users must migrate), and FortiPAM 1.8.3 or above (all earlier FortiPAM branches must migrate to a supported fixed release). A virtual patch (FG-VD-10009513.0day) is available in FMWP database update 26.062 for organizations using FortiManager with virtual patching enabled. As additional mitigations, restrict management interface access to trusted IP addresses only and enforce the principle of least privilege for administrative accounts. Use Fortinet's upgrade path tool at https://docs.fortinet.com/upgrade-tool to plan the appropriate upgrade path (FortiGuard Advisory).
Security news outlets including CyberSecurityNews, GBHackers, CyberPress, and VPNcentral covered the vulnerability as part of Fortinet's July 2026 patch release addressing seven vulnerabilities across FortiOS, FortiProxy, FortiPAM, and FortiSandbox. Coverage was generally informational, noting the medium severity rating and the requirement for privileged access and ASLR bypass as factors limiting immediate risk. No notable independent researcher commentary or significant social media debate was observed beyond standard vulnerability tracking and aggregation (CyberSecurityNews, GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."