CVE-2026-24641: Fortinet FortiWeb

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requests.

Affected products

  • Fortinet FortiWeb: from 7.0.0, before 7.6.7 (fixed in 7.6.7); from 8.0.0, before 8.0.3 (fixed in 8.0.3)

Published 2026-03-10. Last modified 2026-06-17.