CVE-2026-24017General(fortinet / fortiweb)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to bypass the authentication rate-limit via crafted requests. The success of the attack depends on the attacker's resources and the password target complexity.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-799

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortiweb

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-17)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
fortiweb

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-03-17: 2Technical Details · 2026-03-12: 1Technical Details · 2026-03-17: 203-1203-1303-17
Signal classification2 categories
General
250.0%
Disclosure
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-121
General1
2026-03-131
General1
2026-03-172
Disclosure2
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-24017 An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.… https://www.cve.org/CVERecord?id=CVE-2026-24017

    Post summary

    Announces CVE‑2026‑24017, an Improper Control of Interaction Frequency vulnerability affecting multiple Fortinet FortiWeb versions, without details on exploitation, patches, or PoC.

    00010192
    56.8K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Fortinet ❗ CVE-2026-24018 ❗ CVE-2026-24017 ❗ CVE-2026-22627 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-fortinet-8/ https://t.co/b7lKkphDE9

    Post summary

    The tweet simply lists three Fortinet CVEs and links to a CERT page, offering no further details or actionable information.

    00010125
    6.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-24017 An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.… https://www.cve.org/CVERecord?id=CVE-2026-24017 ----- Traducción: CVE-2026-24017 Vul… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑24017, an Improper Control of Interaction Frequency vulnerability affecting specific Fortinet FortiWeb versions, with a link to the official CVE record.

    0000034
    60 followersView on X
  • DailyCVE@dailycve
    General

    🔴 Fortinet FortiWeb, Improper Control of Interaction Frequency, #CVE-2026-24017 (High) https://dailycve.com/fortinet-fortiweb-improper-control-of-interaction-frequency-cve-2026-24017-high/

    Post summary

    The text merely announces CVE-2026-24017 as a high‑severity FortiWeb flaw labeled 'Improper Control of Interaction Frequency'; it contains no information on PoC, exploit, active use, or patching.

    0000033
    167 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortiweb---

Explore more