Skip to content
FG IR 26 161

FG IR 26 161

fortiguard.fortinet.com • August 13, 2026

A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS explicit proxy may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.

Disable the SOCKS proxy.

Modify the authentication scheme for the SOCKS proxy to not use Kerberos authentication in config authentication rule and config authentication scheme settings.

Virtual Patch named "FG-VD-10009617.0day." is available in FMWP db update 26.073

2026-08-12: Initial publication

Extracted Entities

Attack Types (1)

Platforms (1)

Vulnerabilities (1)