Stack buffer overflow in WAD
CVSSv3 Score: 5.1 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS explicit proxy may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled. Revised on 2026-08-12 00:00:00
CSIRTS triage
- What
- Stack buffer overflow in FortiOS explicit proxy WAD daemon allows arbitrary code execution under specific configuration conditions.
- Who is affected
- FortiOS explicit proxy deployments configured with Kerberos authentication and SOCKS enabled.
- Urgency
- Moderate urgency; CVSS 5.1 requires specific configuration and stack protection bypass, limiting exposure.
- Action
- Update FortiOS to patch CVE-2026-71407 and disable Kerberos+SOCKS explicit proxy if not required.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiOS
Get an email when a new FortiOS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-161
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-714070.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-71407 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Fortinet FortiOS: Multiple vulnerabilities enable code execution and DoScert-bund
- unknownFortinet Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Fortinet products (August 13, 2026)cert-fr-avis
- mediumCVE-2026-71407: A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 …nvd
Recent advisories for Stack buffer overflow
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-72194: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: add depth limit …nvd · 2026-08-15
- highCVE-2026-45699: Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versi…nvd · 2026-08-14
- highCVE-2026-18511: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-ba…nvd · 2026-08-13
- highCVE-2026-18077: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to…nvd · 2026-08-13
- highCVE-2026-16815: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and po…nvd · 2026-08-13
- mediumCVE-2026-16692: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of …nvd · 2026-08-13
More from Fortinet FortiGuard PSIRT
- unknownServer-Side Request Forgery (SSRF)2026-08-12
- unknownContent-Encoding WAF Evasion2026-08-12
- unknownFGFM Authentication Weakening via CLI Configuration2026-08-12
- unknownHeap overflow in kernel driver due to missing size validation2026-08-12
- unknownHTTP/2 Bomb CVE-2026-499752026-08-12