ZeroHour
Fortinet PSIRTpublished ()ingested

Null Pointer Dereference in Log Report

lowAdvisoryimportance 12
AI summary · glm-5.3

Fortinet patched a low-severity null pointer dereference (CVSS 2.5) in FortiOS, FortiProxy, and FortiPAM that lets authenticated attackers crash the httpsd daemon.

Fortinet advisory FG-IR-26-173 describes a NULL pointer dereference vulnerability (CWE-476) in FortiOS, FortiProxy, and FortiPAM, scored CVSSv3 2.5. An authenticated attacker can crash the httpsd daemon via crafted HTTP requests, causing a denial of service. The advisory was revised on 2026-09-08.

  • CVSSv3 2.5 null pointer dereference (CWE-476) in httpsd
  • Affects FortiOS, FortiProxy, and FortiPAM
  • Authenticated attacker can crash httpsd via crafted HTTP requests
Full article

CVSSv3 Score: 2.5 A NULL Pointer Dereference vulnerability [CWE-476] in FortiOS, FortiProxy and FortiPAM may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests. Revised on 2026-09-08 00:00:00

This source does not provide full text. Read it at fortiguard.fortinet.com.