CVE-2026-59840
FortiOS vulnerability analysis and mitigation

Overview

CVE-2026-59840 is a buffer over-read vulnerability (CWE-126) in Fortinet FortiOS, FortiProxy, and FortiSASE that may allow an authenticated remote attacker to return a portion of device memory via a specially crafted request. It was published on July 14, 2026, under Fortinet PSIRT advisory FG-IR-26-154. Affected products include FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, and all versions of 7.2, 7.0, and 6.4; FortiProxy 7.6.0–7.6.5, 7.4.0–7.4.13, and all versions of 7.2 and 7.0; as well as FortiPAM and FortiSwitchManager across multiple versions. The vulnerability carries a CVSS v3.1 base score of 4.1–4.3 (Medium) (FortiGuard Advisory).

Technical details

The vulnerability is classified as CWE-126 (Buffer Over-read), occurring in the authd and wad daemon components of FortiOS and FortiProxy. An authenticated attacker can submit a specially crafted request that causes the affected daemon to read beyond the intended buffer boundary, returning a portion of device memory in the redirect response. Exploitation requires network access and low-level authenticated privileges (PR:L), with no user interaction needed. The attack vector is network-based with low complexity, and the scope is unchanged, limiting impact to confidentiality only (FortiGuard Advisory).

Impact

Successful exploitation results in partial information disclosure — specifically, an authenticated attacker can read adjacent memory contents returned in HTTP redirect responses from the affected device. This could expose sensitive in-memory data such as credentials, session tokens, or configuration fragments. There is no integrity or availability impact, and the vulnerability does not enable remote code execution or lateral movement on its own (FortiGuard Advisory).

Exploitation steps

  1. Authentication: Obtain low-privileged credentials to a vulnerable FortiOS or FortiProxy instance (e.g., via phishing, credential stuffing, or insider access).
  2. Identify target endpoint: Locate the authentication or web proxy interface (authd/wad daemon) exposed on the device's management or data plane.
  3. Craft malicious request: Construct a specially crafted HTTP request targeting the vulnerable daemon that triggers an out-of-bounds read condition in the buffer handling logic.
  4. Capture redirect response: Submit the crafted request and capture the HTTP redirect response, which may contain a portion of device memory beyond the intended buffer boundary.
  5. Extract sensitive data: Analyze the leaked memory content for sensitive information such as credentials, session tokens, or internal configuration data (FortiGuard Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to FortiOS/FortiProxy authentication endpoints (authd/wad) with malformed or oversized parameters from authenticated sessions; unexpected redirect responses with anomalous body content or unusual lengths.
  • Logs: FortiOS/FortiProxy access logs showing repeated authenticated requests to authentication or proxy endpoints with crafted inputs; daemon crash or error logs from authd or wad processes.
  • Process: Unexpected memory access errors or core dumps associated with the authd or wad daemons on the FortiOS/FortiProxy device.

Mitigation and workarounds

Fortinet has released patched versions: FortiOS 7.6.4 or above (for 7.6.x), FortiOS 7.4.9 or above (for 7.4.x); users on FortiOS 7.2, 7.0, or 6.4 should migrate to a fixed release. FortiProxy users should upgrade to 7.6.6 or above (for 7.6.x) or 7.4.14 or above (for 7.4.x); FortiProxy 7.2 and 7.0 users should migrate to a fixed release. A virtual patch named FG-VD-58646.0day is available in FMWP database update 26.010 for organizations unable to upgrade immediately. Restricting network access to management interfaces to trusted administrators and implementing network segmentation are recommended interim mitigations (FortiGuard Advisory).

Community reactions

The vulnerability was reported under responsible disclosure by Vang3lis and Cyth from VARAS@IIE, and Fortinet acknowledged their contribution in the advisory. No significant public researcher commentary, social media discussion, or media coverage has been identified beyond standard vulnerability tracking aggregators (FortiGuard Advisory).

Additional resources


SourceThis report was generated using AI

Related FortiOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59837MEDIUM6.6
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026
CVE-2026-23573MEDIUM6.1
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026
CVE-2026-59839MEDIUM5.5
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026
CVE-2026-59840MEDIUM4.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026
CVE-2025-62826MEDIUM4.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management