CVE-2026-22828

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortianalyzer_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*

History

01 May 2026, 12:38

Type Values Removed Values Added
CPE cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:*:*:*:*:*:*:*:*
References () https://fortiguard.fortinet.com/psirt/FG-IR-26-121 - () https://fortiguard.fortinet.com/psirt/FG-IR-26-121 - Vendor Advisory
First Time Fortinet
Fortinet fortimanager Cloud
Fortinet fortianalyzer Cloud

14 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-14 16:16

Updated : 2026-05-01 12:38


NVD link : CVE-2026-22828

Mitre link : CVE-2026-22828

CVE.ORG link : CVE-2026-22828


JSON object : View

Products Affected

fortinet

  • fortianalyzer_cloud
  • fortimanager_cloud
CWE
CWE-122

Heap-based Buffer Overflow