CVE-2026-24641Disclosure(fortinet / fortiweb)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requests.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortiweb

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-17)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
fortiweb

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-03-17: 2PoC Mentioned / Linked · 2026-03-12: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-17: 203-1203-1303-17
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-121
Disclosure1
2026-03-131
Disclosure1
2026-03-172
Disclosure2
Full discourse4 posts
  • DailyCVE@dailycve
    Disclosure

    🔵 Fortinet FortiWeb, NULL Pointer Dereference, #CVE-2026-24641 (Low) https://dailycve.com/fortinet-fortiweb-null-pointer-dereference-cve-2026-24641-low/

    Post summary

    The post announces a newly identified NULL pointer dereference vulnerability (CVE‑2026‑24641) in Fortinet FortiWeb with low severity, linking to an external CVE article.

    0001036
    168 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-24641 A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, Fo… https://www.cve.org/CVERecord?id=CVE-2026-24641 ----- Traducción: CVE-2026-24641 Una… http://infoflow.cloud`

    Post summary

    The post announces a zero‑day null‑pointer dereference vulnerability in Fortinet FortiWeb across several major versions, linking to the official CVE record.

    0000034
    60 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24641 A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, Fo… https://www.cve.org/CVERecord?id=CVE-2026-24641

    Post summary

    The text explains that CVE-2026-24641 is a NULL Pointer Dereference vulnerability affecting multiple FortiWeb versions, but does not mention exploitation, PoC, patches or mitigations.

    00000172
    56.8K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    📝 CVE-2026-24641: Fortinet (CVSS: 2.5)... FortiWeb's NULL pointer dereference spans 5+ major versions - authenticated DoS with crafted HTTP requests makes this a... https://zerodaysignal.com/vulnerability/CVE-2026-24641 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post discloses CVE-2026-24641, describing a null pointer dereference in FortiWeb that can lead to authenticated DoS across multiple versions, providing technical details but no exploit code or patch information.

    0000062
    143 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortiweb---

Explore more