Stack-based buffer overflow in Fortinet, Inc products - CVE-2026-59837
Published: July 14, 2026
Vulnerability identifier: #VU137525
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59837
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to stack-based buffer overflow in Log Report. A privileged authenticated attacker who can bypass stack protection and aslr can execute arbitrary code or commands via crafted HTTP requests.
Affected software
FortiPAM
FortiProxy
FortiOS
FortiProxy
FortiOS
How to mitigate CVE-2026-59837
Install update from vendor's website.
FortiPAM - update to 1.8.3
FortiProxy - update to 7.4.14
FortiOS - update to 7.4.2
FortiProxy - update to 7.4.14
FortiOS - update to 7.4.2