CVE-2026-71407Disclosure(fortinet / fortios)

MEDIUMCVSS 8.1 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch fortinet fortios systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-08-13)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
fortios

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-12: 1Mentions · 2026-08-13: 2Active Exploitation · 2026-08-13: 1Patch / Workaround · 2026-08-13: 1Technical Details · 2026-08-12: 1Technical Details · 2026-08-13: 108-1208-13
Signal classification3 categories
Disclosure
133.3%
Active Exploitation
133.3%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-121
Disclosure1
2026-08-132
Active Exploitation1Patch1
Full discourse3 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting Fortinet FortiPAM and other products (CVE-2026-71407) https://vuldb.com/vuln/388989/cti

    Post summary

    This post notes increased threat actor activity targeting Fortinet FortiPAM tied to CVE‑2026‑71407, implying active exploitation but offering no PoC, patch, or detailed vulnerability data.

    01010146
    2.3K followersView on X
  • Merge News@mergenewsapp
    Patch

    FortiOS explicit proxy users face RCE risk (CVE-2026-71407) if Kerberos and SOCKS are enabled. Patch immediately to prevent network compromise. #fortios #vulnerability #networksecurity #bufferoverflow https://merge.news/post/FevCTFfHAdPowU0GFQAL

    Post summary

    The advisory warns FortiOS users of a remote code execution vulnerability (CVE‑2026‑71407) when Kerberos and SOCKS are enabled and urges an immediate patch to protect the network.

    0000040
    41 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-71407 FortiOS 7.6.1-7.6.6 Stack Buffer Overflow Allows Arbitrary Code E... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-71407 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The text announces a stack buffer overflow vulnerability (CVE‑2026‑71407) in FortiOS 7.6.1‑7.6.6, referencing potential arbitrary code execution and linking to more details, but does not provide any PoC, exploit, or patch information.

    0000094
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---

Explore more