UI DoS attack

MonitorCVSS 5FG-IR-26-162Aug 12, 2026
Fortinet
IT in OT - Fortinet products are commonly deployed at IT/OT network boundaries
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A vulnerability in FortiOS allows an unauthenticated remote attacker to trigger a denial-of-service condition on the web management interface by sending a series of slow or malformed HTTP requests. The application fails to properly handle or timeout these requests, consuming resources and rendering the management interface unresponsive. This prevents administrators from accessing the firewall for configuration, monitoring, or incident response.

What this means
What could happen
An attacker can send specially crafted network requests to cause the FortiGate web management interface to become unresponsive, preventing administrators from accessing the firewall's configuration and monitoring capabilities.
Who's at risk
FortiGate firewall administrators at any organization using FortiOS 7.2, 7.4, or 7.6.0–7.6.6. This affects the management and visibility capability of the firewall; while not directly impacting production traffic, inability to manage the firewall can prevent incident response and policy changes during an active attack.
How it could be exploited
An attacker sends a series of slow or malformed HTTP requests to the FortiGate management interface (typically port 443 or 8443). The application fails to properly timeout or reject these requests, consuming resources until the web interface becomes unresponsive. The attacker needs only network access to the management interface—no credentials or special configuration required.
Prerequisites
  • Network access to FortiGate management interface (port 443 or 8443)
  • No authentication required
remotely exploitableno authentication requiredlow complexity
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (3)
3 with fix
ProductAffected VersionsFix Status
FortiOS7.6.0 - 7.6.67.6.7+
FortiOS7.4 all versionsMigrate to fixed release
FortiOS7.2 all versionsMigrate to fixed release
Remediation & Mitigation
0/4
Do now
0/1
HARDENINGRestrict network access to the FortiGate management interface to trusted administrative networks only using upstream firewall or internal network segmentation
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

FortiOS
HOTFIXUpdate FortiOS 7.6 devices to version 7.6.7 or later
HOTFIXFor FortiOS 7.4 and 7.2 devices, plan a migration to a supported fixed release (7.6.7 or later) as part of your maintenance schedule
Long-term hardening
0/1
HARDENINGMonitor FortiGate web interface availability and administrator login success rates for signs of DoS activity
API: /api/v1/advisories/6799dbb1-0196-49c2-8345-e4f86ced4360

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

UI DoS attack | CVSS 5 - OTPulse