SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-84392

LOW · CVSS 2.7 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Fortinet's FortiOS and FortiPAM products, as well as specific versions of FortiProxy, are vulnerable to a NULL Pointer Dereference, which could allow an authenticated attacker to crash the httpsd daemon through specially crafted HTTP requests. While the severity is rated low, organizations using these products should prioritize patching to prevent potential service disruptions. This is particularly relevant for system administrators and security teams managing Fortinet infrastructure.

CVE
CVE-2026-84392
Severity
LOW
CVSS
2.7
EPSS
0.28%
Fortinet FortiOS

Original NVD Description

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.6, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests.