Skip to content
FortiOS and FortiSwitchManager Vulnerability Allows Remote Arbitrary Code Execution

FortiOS and FortiSwitchManager Vulnerability Allows Remote Arbitrary Code Execution

Cybersecuritynews •Guru Baran • January 13, 2026

Fortinet has disclosed a critical heap-based buffer overflow vulnerability (CWE-122) in the cw_acd daemon of FortiOS and FortiSwitchManager. This flaw enables a remote, unauthenticated attacker to execute arbitrary code or commands by sending specially crafted requests over the network. Organizations relying on Fortinet’s firewalls, secure access service edge (SASE) solutions, and switch management tools face […]

Extracted Entities

Vulnerabilities (1)