---
id: CVE-2026-71407
title: >-
  A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in
  Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who
  can bypass stack protection and ASLR to execute arbitrary code or commands in
  the conte…
summary: >-
  A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in
  Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who
  can bypass stack protection and ASLR to execute arbitrary code or commands in
  the conte…
severity: medium
cvss: 5.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-121
vendor: fortinet
product: fortios
affected:
  - 'fortios >= 7.6.1, < 7.6.7'
patched:
  - fortios 7.6.7
published: '2026-08-12'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:55:21.163'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71407'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-26-161'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.0054
epssPercentile: 0.4436
ingestedAt: '2026-09-08T21:11:12.275Z'
---

## Overview

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.

## Affected

- `fortios >= 7.6.1, < 7.6.7`

## Remediation

Upgrade past the affected range:

- `fortios 7.6.7`
