CVE-2016-6909
CRITICAL EXPLOITEDFortiOS 4.1.0-4.1.10, 4.2.0-4.2.12, 4.3.0-4.3.8 & FortiSwitch <3.4.2 - RCE via Cookie Parser Buffer Overflow
Title source: llmExploitation Summary
CVE-2016-6909 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Shadow Brokers.
AI-analyzed exploit summary This is a stub entry for CVE-2026-6909, referencing an external exploit without providing actual code. It claims to be a remote code execution exploit for Fortigate Firewalls but lacks implementation details.
Description
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
Exploits (1)
This is a stub entry for CVE-2026-6909, referencing an external exploit without providing actual code. It claims to be a remote code execution exploit for Fortigate Firewalls but lacks implementation details.
References (6)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H