Status: EPSS-IMMINENT | Advisory ID: CVE-2026-40688
| CVE | CVE-2026-40688 |
| CVSS | CVSS 7.2 (High). |
| Affected products | Fortinet FortiWeb |
| Classified as | CWE-787 (Out-of-bounds Write) |
| Exploitation prediction (EPSS) | 6% probability of exploitation in the next 30 days (93% percentile) -- FIRST.org's EPSS model. |
An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-40688 |
| Vendor advisory | https://fortiguard.fortinet.com/psirt/FG-IR-26-127 |