A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS explicit proxy may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.
Disable the SOCKS proxy.
Modify the authentication scheme for the SOCKS proxy to not use Kerberos authentication in config authentication rule and config authentication scheme settings.
Virtual Patch named "FG-VD-10009617.0day." is available in FMWP db update 26.073
2026-08-12: Initial publication
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
