Format String Vulnerability in CAPWAP fast-failover mode

Summary

A Use of Externally-Controlled Format String vulnerability [CWE-134] in FortiGate may allow an authenticated admin to execute unauthorized code or commands via specifically crafted configuration.

Version Affected Solution
FortiOS 7.6 7.6.0 through 7.6.4 Upgrade to 7.6.5 or above
FortiOS 7.4 7.4.0 through 7.4.9 Upgrade to 7.4.10 or above
FortiOS 7.2 7.2.0 through 7.2.11 Migrate to a fixed release
FortiOS 7.0 7.0 all versions Migrate to a fixed release
FortiOS 6.4 Not affected Not Applicable
Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool

Virtual Patch named "FG-VD-59445.0day." is available in FMWP db update 26.010

Acknowledgement

Internally discovered and reported by Yonghui Han of Fortinet Product Security team.

Timeline

2026-02-10: Initial publication