CVE-2026-59840

MEDIUM

Fortinet FortiOS - Buffer Over-read

Title source: rule
STIX 2.1

Description

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to information disclosure via <insert attack vector here>

References (1)

Core 1

Scores

CVSS v3 4.3
EPSS 0.0018
EPSS Percentile 7.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-126
Status published
Products (22)
Fortinet/FortiOS 6.4.0 - 6.4.16
Fortinet/FortiOS 7.0.0 - 7.0.19
Fortinet/FortiOS 7.2.0 - 7.2.13
fortinet/fortios 7.2.0 - 7.4.9
Fortinet/FortiOS 7.4.0 - 7.4.8
Fortinet/FortiOS 7.6.0 - 7.6.2
Fortinet/FortiOS 7.6.0 - 7.6.3
Fortinet/FortiPAM 1.0.0 - 1.0.3
Fortinet/FortiPAM 1.1.0 - 1.1.2
Fortinet/FortiPAM 1.2.0
... and 12 more
Published Jul 14, 2026
Tracked Since Jul 14, 2026