CVE-2016-6909

CRITICAL EXPLOITED

FortiOS 4.1.0-4.1.10, 4.2.0-4.2.12, 4.3.0-4.3.8 & FortiSwitch <3.4.2 - RCE via Cookie Parser Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2016-6909 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Shadow Brokers.

AI-analyzed exploit summary This is a stub entry for CVE-2026-6909, referencing an external exploit without providing actual code. It claims to be a remote code execution exploit for Fortigate Firewalls but lacks implementation details.

Description

Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.

Exploits (1)

exploitdb STUB
by Shadow Brokers · textwebappshardware
https://www.exploit-db.com/exploits/40276

This is a stub entry for CVE-2026-6909, referencing an external exploit without providing actual code. It claims to be a remote code execution exploit for Fortigate Firewalls but lacks implementation details.

Classification
Stub 50%
Attack Type
Rce
Complexity
Theoretical
Reliability
Theoretical
Target: Fortigate Firewalls (version unspecified)
No auth needed
Prerequisites: Access to the exploit binary from the provided GitLab link
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory x_refsource_confirm
http://fortiguard.com/advisory/FG-IR-16-023
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036643
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40276/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92523

Scores

CVSS v3 9.8
EPSS 0.6341
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2016-09-28
CWE
CWE-119
Status published
Products (2)
fortinet/fortios 4.1.0 - 4.1.11
fortinet/fortiswitch < 3.4.2
Published Aug 24, 2016
Tracked Since Feb 18, 2026