Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities Fortinet PSIRT

Content-Encoding WAF Evasion

  • What: FortiWeb WAF bypass vulnerability via Content-Encoding
  • Impact: Attackers may bypass security policies
Read Full Article →

PSIRT Content-Encoding WAF Evasion Summary An incomplete list of disallowed inputs [CWE-184] in FortiWeb WAF may allow an unauthenticated attacker to bypass policies via specifically crafted requests. Version Affected Solution FortiWeb 8.0 8.0.0 through 8.0.2 Upgrade to 8.0.3 or above FortiWeb 7.6 7.6.0 through 7.6.5 Upgrade to 7.6.6 or above FortiWeb 7.4 7.4 all versions Migrate to a fixed release FortiWeb 7.2 7.2 all versions Migrate to a fixed release Virtual Patch named "FG-VD-10009598.0day." is available in FMWP db update 26.071. Acknowledgement Fortinet is pleased to thank Rui Xi (@Cycloctane) from Beijing University of Posts and Telecommunications for reporting this vulnerability under responsible disclosure. Timeline 2026-08-12: Initial publication IR Number FG-IR-26-157 Published Date Aug 12, 2026 Component GUI Severity Medium Discovered External Attack Type Unauthenticated Known Exploited No CVSSv3 Score 4.8 Impact Improper access control CVE ID CVE-2026-70466 Download CVRF CSAF

Share this article