NULL pointer dereference in Fortinet, Inc products - CVE-2026-84392
Published: September 9, 2026
Vulnerability identifier: #VU148728
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-84392
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to perform service disruption.
The vulnerability exists due to null pointer dereference in Log Report. An authenticated attacker can crash the httpsd daemon via crafted HTTP requests.
Affected software
FortiPAM
FortiProxy
FortiOS
FortiProxy
FortiOS
How to mitigate CVE-2026-84392
Install update from vendor's website.
FortiPAM - update to 1.9.1
FortiProxy - update to 7.6.7
FortiOS - update to 7.6.0
FortiProxy - update to 7.6.7
FortiOS - update to 7.6.0