CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-59837

mediumCVSS 6.6covered by 4 sourcesfirst seen 2026-07-14
CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests. Revised on 2026-07-14 00:00:00

CSIRTS triage

What
A privileged authenticated attacker may execute arbitrary code or commands via crafted HTTP requests.
Who is affected
Privileged authenticated users of FortiOS, FortiProxy, and FortiPAM.
Urgency
Remediation is urgent due to the potential for remote code execution.
Action
Update to the latest versions of FortiOS, FortiProxy, and FortiPAM.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-59837

Get an email if CVE-2026-59837 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (4)

External references

NVD record for CVE-2026-59837

CVE.org record

Embed the live status

CVE-2026-59837 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-59837 status](https://www.csirts.com/badge/CVE-2026-59837)](https://www.csirts.com/cve/CVE-2026-59837)