Content-Encoding WAF Evasion
CVSSv3 Score: 4.8 An incomplete list of disallowed inputs [CWE-184] in FortiWeb WAF may allow an unauthenticated attacker to bypass policies via specifically crafted requests. Revised on 2026-08-12 00:00:00
CSIRTS triage
- What
- Incomplete input validation in FortiWeb WAF allows attackers to bypass security policies via content-encoding evasion.
- Who is affected
- FortiWeb WAF deployments relying on policy enforcement.
- Urgency
- Moderate urgency; CVSS 4.8 compromises WAF effectiveness but does not directly enable code execution.
- Action
- Update FortiWeb to patch CVE-2026-70466 and review WAF policy coverage for encoding bypasses.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiWeb
Get an email when a new FortiWeb advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-157
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-704660.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-70466 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0300 [1.00] [M/H] Vulnerabilities patched in Fortinet FortiWebncsc-nl
- high[NEW] [high] Fortinet FortiWeb: Multiple vulnerabilities enable bypass of security measurescert-bund
- unknownFortinet Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Fortinet products (August 13, 2026)cert-fr-avis
- mediumCVE-2026-70466: A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2,…nvd
More from Fortinet FortiGuard PSIRT
- unknownServer-Side Request Forgery (SSRF)2026-08-12
- unknownFGFM Authentication Weakening via CLI Configuration2026-08-12
- unknownHeap overflow in kernel driver due to missing size validation2026-08-12
- unknownStack buffer overflow in WAD2026-08-12
- unknownHTTP/2 Bomb CVE-2026-499752026-08-12