A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-148 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
15 Jul 2026, 14:50
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Fortinet fortios
Fortinet fortipam Fortinet fortiproxy Fortinet |
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-26-148 - Vendor Advisory | |
| CPE | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:* |
14 Jul 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 16:17
Updated : 2026-07-15 14:50
NVD link : CVE-2026-59837
Mitre link : CVE-2026-59837
CVE.ORG link : CVE-2026-59837
JSON object : View
Products Affected
fortinet
- fortios
- fortiproxy
- fortipam
CWE
CWE-121
Stack-based Buffer Overflow
