Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.5

Fortinet FortiWeb Crashing with Malformed HTTP Requests

CVE-2026-24641
Summary

An attacker can crash the FortiWeb HTTP server by sending specially crafted HTTP requests, which could disrupt services. This vulnerability affects Fortinet FortiWeb versions 7.0, 7.2, 7.4, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.2. Update to the latest version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
fortinet fortiweb > 7.0.0 , <= 7.6.7
fortinet fortiweb > 8.0.0 , <= 8.0.3
Original title
A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiW...
Original description
A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requests.
nvd CVSS3.1 2.7
Vulnerability type
CWE-476 NULL Pointer Dereference
Published: 10 Mar 2026 · Updated: 13 Mar 2026 · First seen: 11 Mar 2026