Skip to content
Beveiligingsnieuws

FortiOS buffer over-read vulnerability: what to do

buffer over-read kwetsbaarheid

FortiGuard Labs has published a PSIRT advisory about a FortiOS buffer over-read vulnerability affecting FortiOS, FortiProxy, and FortiSASE. The issue is classified as a buffer over-read with a CWE-126 identifier, and it can allow an authenticated remote attacker to trigger a response that may contain a portion of device memory.

In plain terms: if an attacker can authenticate and then send a specially crafted request, the redirect response might return more data than intended. While this disclosure does not describe public exploitation details, it does underline the need for prompt review and remediation.

What the FortiOS buffer over-read vulnerability allows

The vulnerability involves a buffer over-read condition. During processing of a crafted request, the system may unintentionally return a fragment of device memory within a redirect response. Because memory disclosure can help an attacker learn information about the system, addressing the flaw is important as part of a broader security hygiene routine.

According to the advisory, the attacker must be authenticated and must act remotely. The affected behavior occurs specifically via a request designed to reach the redirect response path.

Affected products and components

The advisory names the following products as impacted:

  • FortiOS
  • FortiProxy
  • FortiSASE

If you run any of these deployments, treat the PSIRT publication as a trigger to verify whether your version is exposed and whether it aligns with a recommended upgrade or mitigation path.

How to mitigate: follow the recommended upgrade path

The safest remediation step described in the advisory is to follow the recommended upgrade path. Fortinet provides an upgrade path tool through its documentation portal, which you can use to identify the appropriate upgrade steps for your environment.

For organizations that manage multiple appliances or instances, the practical approach is to:

  • Confirm which product(s) and versions are running in production.
  • Compare them against the advisory’s remediation guidance.
  • Plan the upgrade window to minimize downtime and validate configuration changes.

When possible, test the upgrade in a staging environment first, especially if you rely on custom routing, reverse proxy behavior, or policy-heavy configurations.

Virtual patch option: FG-VD-58646.0day

In addition to upgrades, a virtual patch is listed in the advisory. The virtual patch name provided is FG-VD-58646.0day, and it is available via an FMWP db update with version 26.010.

This can be a valuable interim measure when you need time to roll out a full software update. However, a virtual patch typically complements, rather than replaces, the long-term remediation plan—so you should still schedule the recommended upgrade path when feasible.

Update your firmware protection data (FMWP db)

Because the virtual patch is delivered through a database update, you should ensure your security components are updated accordingly. The advisory specifically references FMWP db update 26.010 for this virtual patch.

Operationally, that means you’ll want to confirm that:

  • Your environment supports the referenced virtual patch mechanism.
  • The FMWP database update is applied successfully.
  • Any management and logging systems reflect the update status.

If your organization uses change control approvals, treat the database update as a security-relevant change and document it for auditing and incident response workflows.

Responsible disclosure and advisory timeline

The PSIRT advisory includes a disclosure acknowledgement to the researchers who reported the issue under responsible practices. It also provides a timeline entry indicating the advisory’s initial publication date.

From the timeline:

  • 2026-07-14: Initial publication

This timing can help you decide how quickly you should update your internal risk register and whether additional controls, like temporary monitoring or accelerated patching, are warranted.

Practical checklist for security teams

If you’re responsible for patch management and incident prevention, here’s a focused checklist you can apply right away for the FortiOS buffer over-read disclosure:

  • Inventory: Identify all systems running FortiOS, FortiProxy, or FortiSASE.
  • Assess exposure: Determine which versions are potentially affected based on Fortinet’s upgrade guidance.
  • Plan upgrades: Use the recommended upgrade path tool to map the safest upgrade sequence.
  • Apply virtual patch interim: If upgrades can’t be immediate, apply FG-VD-58646.0day via FMWP db 26.010.
  • Validate: Confirm the update/patch status and ensure your configuration still behaves as expected.
  • Document: Record actions taken, dates applied, and any testing results.

Even when exploitation is not known or not widespread, buffer over-read issues are precisely the kind of vulnerability that merits timely remediation because they can lead to information disclosure.

Why this matters beyond one patch

This advisory highlights a common security reality: memory handling flaws can turn normal protocol behavior—like a redirect response—into a pathway for data leakage. As environments expand to include proxy and SASE components, vulnerabilities can quickly affect multiple product lines.

Therefore, use this disclosure as a prompt to review not only patch status, but also how quickly your organization can coordinate updates across network edge components.

Conclusion

The PSIRT announcement about the FortiOS buffer over-read vulnerability calls for prompt attention. Because an authenticated remote attacker may be able to retrieve a portion of device memory via a specially crafted request, the recommended actions are clear: follow the upgrade path and, where necessary, apply the available virtual patch FG-VD-58646.0day through FMWP db update 26.010.

If you have FortiOS, FortiProxy, or FortiSASE deployments in scope, prioritize inventory checks and remediation planning so you can reduce risk quickly while maintaining operational stability.

Source: https://fortiguard.fortinet.com/psirt/FG-IR-26-154