CVE-2026-71407
CVE-2026-71407: 2 tracked advisory records across Fortinet. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Fortinet
2 advisories- Advisory severityMedium5.1
Medium [CVE-2026-71407] Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled
CVE-2026-71407Source published Source updated
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled. Affected products named by the advisory: FortiProxy.
- Affected products in this advisory
- FortiOS
- Source-reported affected versions
- FortiOS FortiOS: 7.2 through 8.0 (vendor-listed versions)
- Source-reported fixed versions
- FortiOS 7.6: 7.6.7
- Mitigation guidance
- Upgrade per the Affected/Solution table: FortiOS 7.6: 7.6.7.
- Advisory severityMedium5.1
Medium [CVE-2026-71407] Stack buffer overflow in WAD
FG-IR-26-161Source published Source updated
CVSSv3 Score: 5.1 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS explicit proxy may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled. Revised on 2026-08-12 00:00:00
- Affected products in this advisory
- FortiOS
- Source-reported affected versions
- FortiOS FortiOS: 7.2 through 8.0 (vendor-listed versions)
- Source-reported fixed versions
- FortiOS 7.6: 7.6.7
- Mitigation guidance
- Upgrade per the Affected/Solution table: FortiOS 7.6: 7.6.7.
Android app · Google Play
Monitor future Fortinet CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.