Fortinet FortiWeb was found to contain a remotely exploitable denial-of-service flaw, tracked as CVE-2026-39811 and published as ZDI-26-265. The bug is an integer overflow in cgi_buf_alloc during HTTP request handling that can be triggered by a crafted request, causing the server to enter an infinite loop and lose availability. The issue requires authentication, carries a CVSS 6.5 rating, and was reported to Fortinet by Jason McFadyen of Trend Research before Fortinet released a fix.
The disclosure lands against a broader backdrop of sustained attacker interest in Fortinet edge technologies. SANS Internet Storm Center previously reported active scanning tied to Fortinet FortiOS and CVE-2024-21762, underscoring how quickly Fortinet vulnerabilities can attract reconnaissance and exploitation attempts once details emerge. For defenders, the combined picture is clear: apply Fortinet updates promptly, review exposure of management and HTTP interfaces, and monitor for abnormal request patterns targeting Fortinet appliances.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The Zero Day Initiative publicly disclosed the Fortinet FortiWeb vulnerability, describing it as a remotely exploitable but authenticated denial-of-service issue with CVSS 6.5. The advisory stated that crafted requests can force the server into an infinite loop and impact availability.
Fortinet released an update to address the FortiWeb denial-of-service flaw involving an integer overflow in cgi_buf_alloc during HTTP request handling. The fix was issued before public disclosure as part of coordinated vulnerability reporting.
Jason McFadyen of Trend Research reported an integer overflow vulnerability in Fortinet FortiWeb to the vendor. The flaw, later assigned CVE-2026-39811 and ZDI-26-265, could let an authenticated remote attacker trigger an infinite loop and denial of service via crafted HTTP requests.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.