CVE-2026-71407
Last modified
CVE-2026-71407 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.. EPSS estimates a 0.49% chance of exploitation in the next 30 days.
Description
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortios | >= 7.6.1, < 7.6.7 |
References
- https://fortiguard.fortinet.com/psirt/FG-IR-26-161Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-71407?
How severe is CVE-2026-71407?
How do I fix CVE-2026-71407?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-71399Adobe XD is affected by a Buffer Overflow vulnerability that…7.8
- CVE-2026-7140A vulnerability has been found in Totolink A8000RU 7.1cu.643…9.8
- CVE-2026-71401An integer underflow was found in the DHCPv4 packet capture …5.3
- CVE-2026-71402An out-of-bounds read was found in the DHCPv4 packet capture…5.4
- CVE-2026-71403A flaw was found in Rancher Manager. The /v3/users update pa…6.1
- CVE-2026-71404A flaw was found in Rancher Manager. The GlobalRole controll…8.7
- CVE-2026-71408A allocation of resources without limits or throttling vulne…5.3
- CVE-2026-7141A vulnerability was found in vLLM up to 0.19.0. The affected…5.6
- CVE-2026-71415Kirby is an open-source content management system. From 5.0.…7.1
- CVE-2026-71416Headroom compresses data before the data reaches a large lan…8.8
- CVE-2026-71417Lemur manages TLS certificate creation. Prior to 1.9.3, POST…7.3
- CVE-2026-71418Suricata is a network Intrusion Detection System, Intrusion …7.5
Are you affected by CVE-2026-71407?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
