SB2026090975 - NULL pointer dereference in Fortinet products



SB2026090975 - NULL pointer dereference in Fortinet products

Published: September 9, 2026

Security Bulletin ID SB2026090975
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Partial DoS

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) NULL pointer dereference (CVE-ID: CVE-2026-84392)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote privileged user to perform service disruption.

The vulnerability exists due to null pointer dereference in Log Report. An authenticated attacker can crash the httpsd daemon via crafted HTTP requests.


Remediation

Install update from vendor's website.