Stack buffer overflow in WAD
MonitorCVSS 5.1FG-IR-26-161Aug 12, 2026
Fortinet
IT in OT - Fortinet products are commonly deployed at IT/OT network boundaries
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
A stack buffer overflow exists in the WAD (Web Application Delivery) service on FortiGate appliances running FortiOS 7.6.1 through 7.6.6. The vulnerability is remotely exploitable without authentication via a specially crafted network packet. Successful exploitation could cause denial of service or arbitrary code execution on the appliance.
What this means
What could happen
An attacker could overflow a buffer in the WAD (Web Application Delivery) service to crash the FortiGate appliance or potentially execute arbitrary code, disrupting network connectivity and security services for your facility.
Who's at risk
Water utilities, electric utilities, and municipal facilities operating Fortinet FortiGate security appliances as network gateways or firewalls. Affected organizations running FortiOS versions 7.6.1 through 7.6.6 should prioritize patching to prevent service disruption.
How it could be exploited
An attacker sends a specially crafted network packet to the WAD service on the FortiGate appliance. Because the vulnerability requires no authentication and is remotely accessible, the attacker does not need valid credentials. Exploitation causes a stack buffer overflow that could crash the device or allow code execution with appliance privileges.
Prerequisites
- Network access to the FortiGate appliance on the WAD service port
- No authentication required
- FortiOS version 7.6.1 through 7.6.6
remotely exploitableno authentication requiredunauthenticated network accesslow complexity attack
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (1)
ProductAffected VersionsFix Status
FortiOS7.6.1 - 7.6.67.6.7+
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDIf immediate patching is not possible, restrict network access to the WAD service to trusted networks only using firewall rules
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate FortiOS to version 7.6.7 or later
Long-term hardening
0/1HARDENINGMonitor FortiGate logs for unexpected crashes or WAD service errors
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/8ddffd93-10f5-4540-b831-e7a58f52cc0bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.