CVE-2026-71408
CVE-2026-71408: 2 tracked advisory records across Fortinet. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Fortinet
2 advisories- Advisory severityMedium5.0
Medium [CVE-2026-71408] allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack vector here>
CVE-2026-71408Source published Source updated
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service
- Affected products in this advisory
- FortiOS
- Source-reported affected versions
- FortiOS FortiOS: 7.2 through 8.0 (vendor-listed versions)
- Source-reported fixed versions
- FortiOS 7.6: 7.6.7
- FortiOS 7.4: migrate to a fixed release
- FortiOS 7.2: migrate to a fixed release
- Mitigation guidance
- Upgrade per the Affected/Solution table: FortiOS 7.6: 7.6.7; FortiOS 7.4: migrate to a fixed release; FortiOS 7.2: migrate to a fixed release.
- Workarounds
- As a mitigation measure, restrict administrator logins to trusted hosts only, limiting the hosts that can initiate an attack.
- Additionally, it is recommended to disable GUI access on Internet-facing interfaces.
- This incident is a regression from https://fortiguard.fortinet.com/psirt/FG-IR-19-013.
- Advisory severityMedium5.0
Medium [CVE-2026-71408] UI DoS attack
FG-IR-26-162Source published Source updated
CVSSv3 Score: 5.0 An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web interface via crafted HTTP requests. Revised on 2026-08-12 00:00:00
- Affected products in this advisory
- FortiOS
- Source-reported affected versions
- FortiOS FortiOS: 7.2 through 8.0 (vendor-listed versions)
- Source-reported fixed versions
- FortiOS 7.6: 7.6.7
- FortiOS 7.4: migrate to a fixed release
- FortiOS 7.2: migrate to a fixed release
- Mitigation guidance
- Upgrade per the Affected/Solution table: FortiOS 7.6: 7.6.7; FortiOS 7.4: migrate to a fixed release; FortiOS 7.2: migrate to a fixed release.
- Workarounds
- As a mitigation measure, restrict administrator logins to trusted hosts only, limiting the hosts that can initiate an attack.
- Additionally, it is recommended to disable GUI access on Internet-facing interfaces.
- This incident is a regression from https://fortiguard.fortinet.com/psirt/FG-IR-19-013.
Android app · Google Play
Monitor future Fortinet CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.