A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requests.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-089 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
12 Mar 2026, 20:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* | |
| First Time |
Fortinet
Fortinet fortiweb |
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-26-089 - Vendor Advisory |
10 Mar 2026, 18:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-10 18:18
Updated : 2026-03-12 20:10
NVD link : CVE-2026-24641
Mitre link : CVE-2026-24641
CVE.ORG link : CVE-2026-24641
JSON object : View
Products Affected
fortinet
- fortiweb
CWE
CWE-476
NULL Pointer Dereference
