CVE-2026-40688Disclosure(fortinet / fortiweb)

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortiweb

Threat summary

  • Public PoC is present in monitored signal
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-04-15); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
fortiweb

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-04-14: 2Mentions · 2026-04-15: 4Mentions · 2026-04-18: 1PoC Mentioned / Linked · 2026-04-15: 1Technical Details · 2026-04-14: 2Technical Details · 2026-04-15: 4Technical Details · 2026-04-18: 104-1404-1504-18
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-142
Disclosure2
2026-04-154
Disclosure3General1
2026-04-181
Disclosure1
Full discourse7 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-266|CVE-2026-40688] Fortinet FortiWeb cat_cgi_paths Out-Of-Bounds Write Remote Code Execution Vulnerability (CVSS 8.8; Credit: Jason McFadyen of Trend Research) https://www.zerodayinitiative.com/advisories/ZDI-26-266/

    Post summary

    An advisory announces a new Fortinet FortiWeb vulnerability (CVE‑2026‑40688) identified as an out‑of‑bounds write leading to remote code execution, with a CVSS of 8.8 and a link to the zero‑day details.

    00011334
    5.4K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚡ CVE-2026-40688: Fortinet (CVSS: 6.7)... Buffer overflow in FortiWeb's core engine with network reachability - high-privilege RCE that screams "pivot point" for... https://zerodaysignal.com/vulnerability/CVE-2026-40688 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑40688, a buffer overflow in FortiWeb that allows high‑privilege RCE, but offers no exploit code, PoC, or evidence of active use.

    0101099
    218 followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Fortinet FortiWeb cat_cgi_paths Out-Of-Bounds Write Remote Code Execution Vulnerability (CVE-2026-40688) #CVE202640688 #CyberSecurity #FortinetFortiWeb #RemoteCodeExecutionVulnerability https://www.systemtek.co.uk/?p=50743 https://t.co/zVWVi95JaY

    Post summary

    The post is a notification of a newly discovered OOB write RCE vulnerability (CVE‑2026‑40688) in Fortinet FortiWeb’s cat_cgi_paths, but offers no proof of concept, exploit code, or patch details.

    0000075
    1.8K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-40688: Fortinet FortiWeb Out-of-Bounds Write Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04c8XR50

    Post summary

    The linked article provides a high‑level overview of CVE‑2026‑40688, mentioning its type as an out‑of‑bounds write, but it does not disclose PoC code, exploits, active attacks, or patch information.

    0000031
    28 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40688 A out-of-bounds write vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow attacker to execut… https://www.cve.org/CVERecord?id=CVE-2026-40688

    Post summary

    The post announces CVE-2026-40688 as an out-of-bounds write vulnerability in specific FortiWeb versions, noting the potential for attacker execution, but does not provide PoC, exploit code, active exploitation claims, or patch information.

    0000080
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40688 Out-of-Bounds Write Vulnerability in Fortinet FortiWeb 7.4.0 Through 8.0.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40688

    Post summary

    The statement announces the discovery of an out‑of‑bounds write vulnerability in Fortinet FortiWeb versions 7.4.0 to 8.0.3, with a reference link for further details.

    0000054
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-40688 A out-of-bounds write vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.… CVSS 7.2 Full analysis → https://sec.kaitan.id/cves/CVE-2026-40688 #Fortinet #CyberSecurity #InfoSec

    Post summary

    A high‑severity out‑of‑bounds write vulnerability (CVE‑2026‑40688) affecting specific FortiWeb versions has been disclosed, with no active exploitation, PoC, or patch information provided.

    000001
    144 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortiweb---

Explore more