---
id: CVE-2026-59840
title: >-
  A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3,
  FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all
  versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy
  7.4.0 through…
summary: >-
  A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3,
  FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all
  versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy
  7.4.0 through…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-126
vendor: fortinet
product: fortiproxy
affected:
  - 'fortiproxy >= 7.2.0, < 7.4.14'
  - 'fortiproxy >= 7.6.0, < 7.6.6'
  - 'fortios >= 7.2.0, < 7.4.9'
  - 'fortios >= 7.6.0, <= 7.6.2'
patched:
  - fortiproxy 7.6.6
  - fortios 7.4.9
published: '2026-07-14'
updated: '2026-07-16'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59840'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-26-154'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.00313
epssPercentile: 0.21615
ingestedAt: '2026-07-17T13:12:08.465Z'
---

## Overview

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to information disclosure via <insert attack vector here>

## Affected

- `fortiproxy >= 7.2.0, < 7.4.14`
- `fortiproxy >= 7.6.0, < 7.6.6`
- `fortios >= 7.2.0, < 7.4.9`
- `fortios >= 7.6.0, <= 7.6.2`

## Remediation

Upgrade past the affected range:

- `fortiproxy 7.6.6`
- `fortios 7.4.9`
