VDB

CVE-2026-84392

CVE-2026-84392 PUBLISHED CVSS 2.5 LOW

Reported by fortinet · Published September 8, 2026

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.6, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests.

Risk Scores

CVSS 3.1
2.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
FortinetFortiOS7.4.0, 7.2.0, 7.0.0
FortinetFortiProxy7.6.0, 7.4.0, 7.2.0
FortinetFortiPAM1.9.0, 1.8.0, 1.7.0
FortinetFortiOS7.4.0, 7.2.0, 7.0.0
FortinetFortiPAM1.0.0, 1.3.0, 1.2.0
FortinetFortiProxy7.4.0, 7.2.0, 7.6.0

Timeline

  • Sep 8, 2026 Coalition ESS Score
  • Sep 8, 2026 CVE Published
  • Sep 8, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›