- What: A buffer over-read vulnerability in FortiOS, FortiProxy, and FortiSASE could expose device memory.
- Impact: Attackers could gain sensitive information.
PSIRT Buffer overread in authd and wad daemon Summary A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. Version Affected Solution FortiOS 8.0 Not affected Not Applicable FortiOS 7.6 7.6.0 through 7.6.2 Upgrade to 7.6.4 or above FortiOS 7.4 7.4.0 through 7.4.8 Upgrade to 7.4.9 or above FortiOS 7.2 7.2 all versions Migrate to a fixed release FortiProxy 7.6 7.6.0 through 7.6.5 Upgrade to 7.6.6 or above FortiProxy 7.4 7.4.0 through 7.4.13 Upgrade to 7.4.14 or above FortiProxy 7.2 7.2 all versions Migrate to a fixed release Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool Virtual Patch named "FG-VD-58646.0day." is available in FMWP db update 26.010 Acknowledgement Fortinet is pleased to thank Vang3lis and Cyth from VARAS@IIE for reporting this vulnerability under responsible disclosure. Timeline 2026-07-14: Initial publication IR Number FG-IR-26-154 Published Date Jul 14, 2026 Component CLI Severity Medium Discovered External Attack Type Authenticated Known Exploited No CVSSv3 Score 4.1 Impact Information disclosure CVE ID CVE-2025-43892 CVE-2026-59840 Download CVRF CSAF