CVE-2023-34984: Fortinet FortiWeb

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.

Affected products

  • Fortinet FortiWeb: from 6.3.6, up to and including 6.3.23; from 6.4.0, up to and including 6.4.3; from 7.0.0, up to and including 7.0.6; from 7.2.0, up to and including 7.2.1

Published 2023-09-13. Last modified 2026-06-17.