VDB
CVE-2026-84392
CVE-2026-84392
PUBLISHED
CVSS 2.5 LOW
Reported by fortinet · Published September 8, 2026
A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.6, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests.
Risk Scores
CVSS 3.1
2.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | FortiOS | 7.4.0, 7.2.0, 7.0.0 |
| Fortinet | FortiProxy | 7.6.0, 7.4.0, 7.2.0 |
| Fortinet | FortiPAM | 1.9.0, 1.8.0, 1.7.0 |
| Fortinet | FortiOS | 7.4.0, 7.2.0, 7.0.0 |
| Fortinet | FortiPAM | 1.0.0, 1.3.0, 1.2.0 |
| Fortinet | FortiProxy | 7.4.0, 7.2.0, 7.6.0 |
Timeline
- Sep 8, 2026 Coalition ESS Score
- Sep 8, 2026 CVE Published
- Sep 8, 2026 CVE Updated