# CVE-2026-84392

## Summary

- **CVE ID:** CVE-2026-84392
- **Severity:** LOW
- **CVSS Score:** 2.5 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C)
- **CWE:** CWE-476
- **Published:** Sep 8, 2026
- **Last Modified:** Sep 8, 2026

## Description

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.6, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests.

## Affected Products

- Fortinet — FortiOS (7.4.0)
- Fortinet — FortiOS (7.2.0)
- Fortinet — FortiOS (7.0.0)
- Fortinet — FortiOS (6.4.0)
- Fortinet — FortiProxy (7.6.0)
- Fortinet — FortiProxy (7.4.0)
- Fortinet — FortiProxy (7.2.0)
- Fortinet — FortiPAM (1.9.0)
- Fortinet — FortiPAM (1.8.0)
- Fortinet — FortiPAM (1.7.0)
- Fortinet — FortiPAM (1.6.0)
- Fortinet — FortiPAM (1.5.0)
- Fortinet — FortiPAM (1.4.0)
- Fortinet — FortiPAM (1.3.0)
- Fortinet — FortiPAM (1.2.0)
- Fortinet — FortiPAM (1.1.0)
- Fortinet — FortiPAM (1.0.0)

## References

- [CNA](https://fortiguard.fortinet.com/psirt/FG-IR-26-173)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.28%
- **EPSS Percentile:** 20.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._