HTTP/2 Bomb CVE-2026-49975

Act NowCVSS 5.8FG-IR-26-163Aug 12, 2026
Fortinet
IT in OT - Fortinet products are commonly deployed at IT/OT network boundaries
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

HTTP/2 Bomb (CVE-2026-49975) is a denial-of-service vulnerability in Fortinet FortiPAM, FortiProxy, and FortiSwitchManager. An attacker can send specially crafted HTTP/2 requests that cause the affected device to crash or become unresponsive, disrupting network operations and administrative access. The vulnerability affects multiple versions across these product lines, with some versions having no fix currently available from Fortinet.

What this means
What could happen
An attacker can send specially crafted HTTP/2 requests to cause a denial of service, making the affected gateway or access control device unavailable and disrupting network traffic or administrative access to critical systems.
Who's at risk
Organizations running Fortinet gateway and access control appliances (FortiPAM, FortiProxy, FortiSwitchManager) used for network security, privileged access management, and switching control. This affects administrators who depend on these devices for network traffic filtering, secure access to critical systems, and infrastructure management.
How it could be exploited
An attacker on the network sends malformed HTTP/2 requests to the device's management interface or proxy service. The device crashes or becomes unresponsive due to improper handling of these requests, denying service to legitimate users and administrators.
Prerequisites
  • Network access to the HTTP/2 service on the affected device (typically port 443 or management interface port)
  • No authentication required to send malicious requests
Remotely exploitableNo authentication requiredLow complexity attackHigh EPSS score (28%)Multiple affected product versions with no patch available
Exploitability
Likely to be exploited — EPSS score 34.3%
Public Proof-of-Concept (PoC) on GitHub (10 repositories)
Affected products (7)
3 with fix4 pending
ProductAffected VersionsFix Status
FortiPAM1.9.0 - 1.9.1No fix yet
FortiPAM1.8 all versionsMigrate to fixed release
FortiPAM1.7 all versions and 7 moreMigrate to fixed release
FortiProxy7.6.0 - 7.6.6No fix yet
FortiProxy7.4.0 - 7.4.14No fix yet
FortiProxy7.2 all versionsMigrate to fixed release
FortiSwitchManager7.2.0 - 7.2.9No fix yet
Remediation & Mitigation
0/6
Do now
0/2
HARDENINGRestrict network access to HTTP/2 management and proxy ports to trusted administrative networks only
WORKAROUNDMonitor affected devices for unexpected restarts or service unavailability as indicators of exploitation attempts
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

FortiPAM
HOTFIXFor FortiPAM 1.7, 1.8: Upgrade to FortiPAM 2.0 or later
FortiProxy
HOTFIXFor FortiProxy 7.2: Upgrade to FortiProxy 7.4.15 or later
HOTFIXFor FortiProxy 7.4.0–7.4.14 and 7.6.0–7.6.6: Contact Fortinet for patched release availability or prepare for forced upgrade timeline
FortiSwitchManager
HOTFIXFor FortiSwitchManager 7.2.0–7.2.9: Contact Fortinet for patch status or plan migration to fixed version
API: /api/v1/advisories/8372b95d-b569-4a5c-aca4-9c1eac050716

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

HTTP/2 Bomb CVE-2026-49975 | CVSS 5.8 - OTPulse