Skip to content
VulniPulse

Fortinet FortiWeb Vulnerabilities & Security Advisories

12 advisories tracked · FortiGuard PSIRT Advisories · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Fortinet advisory that VulniPulse classified as FortiWeb, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 3 critical, 1 high, 7 medium, 1 low.

Android app · Google Play

Monitor Fortinet CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

FortiGuard PSIRT Advisories

Polled via the official FortiGuard PSIRT RSS feed (filestore.fortinet.com). PSIRT pages are fetched for new items to extract affected and fixed versions.

Latest Fortinet FortiWeb advisories

Medium6.7Fortinet

Medium [CVE-2026-40688] Out-Of-Bounds Write in administrative interface

CVSSv3 Score: 6.7 An out-of-bounds write vulnerability [CWE-787] in FortiWeb CGI daemon may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests. Revised on 2026-04-15 00:00:00

CVE-2026-40688
FortiWeb
Apr 15, 2026
Medium4.4Fortinet

Medium [CVE-2026-39811] Integer Overflow Denial of Service in administrative interface

CVSSv3 Score: 4.4 An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiWeb may allow a privileged authenticated attacker to perform a denial of service of the system via crafted HTTP requests. Revised on 2026-04-14 00:00:00

CVE-2026-39811
FortiWeb
Apr 14, 2026
Medium6.2Fortinet

Medium [CVE-2026-39814] Multiple Path traversals in CLI

CVSSv3 Score: 6.2 Multiple Relative Path Traversal vulnerabilities [CWE-23] in FortiWeb may allow a local privileged attacker to execute unauthorized code on the underlying system via crafted CLI commands. Revised on 2026-04-14 00:00:00

CVE-2026-39814
FortiWeb
Apr 14, 2026
Medium5.9Fortinet

Medium [CVE-2026-30897] stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb…

A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.

CVE-2026-30897
FortiWeb
Mar 10, 2026
Medium5.9Fortinet

Medium [CVE-2026-24640] Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0…

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0.2 through 7.0.12 may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.

CVE-2026-24640
FortiWeb
Mar 10, 2026
Medium6.7Vendor: HighFortinet

Medium [CVE-2025-66178] improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb…

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow an authenticated attacked to execute arbitrary commands via a specialy crafted HTTP request.

CVE-2025-66178
FortiWeb
Mar 10, 2026
Medium5.0Fortinet

Medium [CVE-2025-48840] authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8…

An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unauthenticated attacker to bypass hostname restrictions via a specially crafted request.

CVE-2025-48840
FortiWeb
Mar 10, 2026

← All Fortinet advisories