A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-121 |
|
History
Wed, 15 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heap Based Buffer Overflow in Fortinet FortiAnalyzer Cloud and FortiManager Cloud Allowing Remote Code Execution |
Wed, 15 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet fortianalyzer Cloud
Fortinet fortimanager Cloud |
|
| Vendors & Products |
Fortinet fortianalyzer Cloud
Fortinet fortimanager Cloud |
Tue, 14 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation | |
| First Time appeared |
Fortinet
Fortinet fortianalyzercloud Fortinet fortimanagercloud |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:2.3:a:fortinet:fortianalyzercloud:7.6.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortianalyzercloud:7.6.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortianalyzercloud:7.6.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortimanagercloud:7.6.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortimanagercloud:7.6.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortimanagercloud:7.6.4:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet fortianalyzercloud Fortinet fortimanagercloud |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-04-15T03:58:26.193Z
Reserved: 2026-01-12T08:32:04.788Z
Link: CVE-2026-22828
Updated: 2026-04-14T16:36:59.949Z
Status : Received
Published: 2026-04-14T16:16:37.110
Modified: 2026-04-14T16:16:37.110
Link: CVE-2026-22828
No data.
OpenCVE Enrichment
Updated: 2026-04-15T15:30:06Z