Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 2 advisories

CVE-2026-71408

CVE-2026-71408: 2 tracked advisory records across Fortinet. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Fortinet

2 advisories
  • Advisory severityMedium5.0

    Medium [CVE-2026-71408] allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack vector here>

    CVE-2026-71408Source published Source updated

    A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service

    Affected products in this advisory
    • FortiOS
    Source-reported affected versions
    • FortiOS FortiOS: 7.2 through 8.0 (vendor-listed versions)
    Source-reported fixed versions
    • FortiOS 7.6: 7.6.7
    • FortiOS 7.4: migrate to a fixed release
    • FortiOS 7.2: migrate to a fixed release
    Mitigation guidance
    • Upgrade per the Affected/Solution table: FortiOS 7.6: 7.6.7; FortiOS 7.4: migrate to a fixed release; FortiOS 7.2: migrate to a fixed release.
    Workarounds
    • As a mitigation measure, restrict administrator logins to trusted hosts only, limiting the hosts that can initiate an attack.
    • Additionally, it is recommended to disable GUI access on Internet-facing interfaces.
    • This incident is a regression from https://fortiguard.fortinet.com/psirt/FG-IR-19-013.
  • Advisory severityMedium5.0

    Medium [CVE-2026-71408] UI DoS attack

    FG-IR-26-162Source published Source updated

    CVSSv3 Score: 5.0 An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web interface via crafted HTTP requests. Revised on 2026-08-12 00:00:00

    Affected products in this advisory
    • FortiOS
    Source-reported affected versions
    • FortiOS FortiOS: 7.2 through 8.0 (vendor-listed versions)
    Source-reported fixed versions
    • FortiOS 7.6: 7.6.7
    • FortiOS 7.4: migrate to a fixed release
    • FortiOS 7.2: migrate to a fixed release
    Mitigation guidance
    • Upgrade per the Affected/Solution table: FortiOS 7.6: 7.6.7; FortiOS 7.4: migrate to a fixed release; FortiOS 7.2: migrate to a fixed release.
    Workarounds
    • As a mitigation measure, restrict administrator logins to trusted hosts only, limiting the hosts that can initiate an attack.
    • Additionally, it is recommended to disable GUI access on Internet-facing interfaces.
    • This incident is a regression from https://fortiguard.fortinet.com/psirt/FG-IR-19-013.

Android app · Google Play

Monitor future Fortinet CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery