CVE-2024-26006

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 14, 2025
CWE ID 79

Summary

CVE-2024-26006 is a Cross-Site Scripting (XSS) vulnerability affecting FortiOS versions 7.4.3 and below, 7.2.7 and below, and 7.0.13 and below, as well as FortiProxy versions 7.4.3 and below, 7.2.9 and below, and 7.0.16 and below. An attacker can exploit this improper neutralization of input during web page generation issue (CWE-79) in the web SSL VPN UI to inject malicious scripts. Successful exploitation may allow the attacker to gain unauthorized access to user data or take control of user sessions, posing a significant risk to confidentiality and integrity. Users are strongly urged to update their FortiOS and FortiProxy systems to the latest versions to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share