CVE-2016-6909: Fortinet FortiOS
Critical severity, CVSS 9.8. EPSS: 49.9% chance of exploitation in the next 30 days.
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
Affected products
- Fortinet FortiOS: from 4.1.0, before 4.1.11 (fixed in 4.1.11); from 4.2.0, before 4.2.13 (fixed in 4.2.13); from 4.3.0, before 4.3.9 (fixed in 4.3.9)
- Fortinet Fortiswitch: up to and including 3.4.2
Published 2016-08-24. Last modified 2026-06-17.