CVE-2026-24641

LOW

FortiWeb 7.0.0-7.6.6, 8.0.0-8.0.2 - Authenticated Denial of Service via HTTP Request

Title source: llm
STIX 2.1

Description

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requests.

References (1)

Core 1
Core References

Scores

CVSS v3 2.7
EPSS 0.0039
EPSS Percentile 30.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (1)
fortinet/fortiweb 7.0.0 - 7.6.7
Published Mar 10, 2026
Tracked Since Mar 11, 2026