Medium [CVE-2026-71408] UI DoS attack
This medium-severity Fortinet advisory covers CVE-2026-71408 affecting FortiOS.
Android app · Google Play
Monitor future Fortinet CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
CVSSv3 Score:
5.0
An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web interface via crafted HTTP requests.
Revised on 2026-08-12 00:00:00
- FortiOS 7.6: 7.6.0 through 7.6.6
- FortiOS 7.4: 7.4 all versions
- FortiOS 7.2: 7.2 all versions
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
- FortiOS 7.6: 7.6.7
- FortiOS 7.4: migrate to a fixed release
- FortiOS 7.2: migrate to a fixed release
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Mitigation checklist
- Upgrade per the Affected/Solution table: FortiOS 7.6: 7.6.7; FortiOS 7.4: migrate to a fixed release; FortiOS 7.2: migrate to a fixed release.
- As a mitigation measure, restrict administrator logins to trusted hosts only, limiting the hosts that can initiate an attack.
- Additionally, it is recommended to disable GUI access on Internet-facing interfaces.
- This incident is a regression from https://fortiguard.fortinet.com/psirt/FG-IR-19-013.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.