SB2026090975 - NULL pointer dereference in Fortinet products
Published: September 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-84392)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote privileged user to perform service disruption.
The vulnerability exists due to null pointer dereference in Log Report. An authenticated attacker can crash the httpsd daemon via crafted HTTP requests.
Remediation
Install update from vendor's website.