Security Advisory Desk
highQCS priority 87/100Fortinet

Fortinet FortiOS CAPWAP Out-of-Bounds Write Vulnerability

Fortinet has fixed a high-severity FortiOS vulnerability in the CAPWAP daemon. In practical terms, an attacker who already controls an authenticated FortiAP, FortiExtender, or FortiSwitch could use that trusted device relationship to gain execution privileges on the connected FortiGate. Internet-wide unauthenticated exploitation is not the scenario described by Fortinet, but environments with managed extension devices should verify versions and trust relationships promptly.

Published 12/5/2026, 12:00:00 amVerified 3/8/2026, 8:35:26 pmRevision 2
Fortinet high network security advisory visual

In plain language

What this advisory means

Fortinet has fixed a high-severity FortiOS vulnerability in the CAPWAP daemon. In practical terms, an attacker who already controls an authenticated FortiAP, FortiExtender, or FortiSwitch could use that trusted device relationship to gain execution privileges on the connected FortiGate. Internet-wide unauthenticated exploitation is not the scenario described by Fortinet, but environments with managed extension devices should verify versions and trust relationships promptly.

Technical explanation

How the issue affects the environment

CVE-2025-53844 is an out-of-bounds write (CWE-787) in the FortiOS CAPWAP daemon. CAPWAP supports communication between a FortiGate and managed extension devices. Fortinet states that exploitation requires control of an authenticated FortiAP, FortiExtender, or FortiSwitch. A crafted interaction from that trusted device can corrupt memory in the daemon and may provide execution privileges on the FortiGate. The important security boundary is therefore the authenticated fabric or device-management relationship, not simply public exposure of the firewall management interface.

Operational impact

Why teams should care

A successful attack could turn a compromised managed access point, extender, or switch into a path for executing unauthorized code or commands on the FortiGate. That can affect the confidentiality and integrity of firewall policy, routing, VPN, segmentation, and traffic inspection. Priority should be highest where downstream devices are administered by separate teams, deployed in less-trusted locations, or have weak lifecycle and credential controls.

Immediate action

Use the Fortinet Upgrade Path Tool and move each affected FortiGate to FortiOS 7.6.4 or later, 7.4.9 or later, or 7.2.12 or later as appropriate for its release train. Back up the configuration, preserve relevant logs, follow change control, validate managed-device connectivity after the upgrade, and confirm the running build rather than treating a completed installation job as evidence of remediation.

Affected and fixed releases

Affected versionsFortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11
Fixed versionsFortiOS 7.6.4 or later, FortiOS 7.4.9 or later, FortiOS 7.2.12 or later

Temporary risk reduction

When immediate patching is not possible, Fortinet documents disabling the CAPWAP daemon by entering global configuration, opening system global, setting wireless-controller to disable, and ending the configuration. Validate the resulting wireless-controller and FortiExtender state exactly as described in the official advisory. This containment can remove managed wireless or extension-device functionality, so assess service impact and obtain change approval before applying it.

Evidence and validation checklist

  • Inventory FortiGate appliances running FortiOS 7.6, 7.4, or 7.2 and record the exact installed build.
  • Identify every FortiAP, FortiExtender, and FortiSwitch authenticated to each FortiGate and confirm its owner and location.
  • Verify whether wireless-controller or related extension-device functions are enabled and operationally required.
  • Review device authorization, configuration changes, administrator activity, and relevant CAPWAP or fabric events for unexpected behavior.
  • Record the approved upgrade path, configuration backup, maintenance window, and rollback plan before patching.
  • After remediation, confirm the fixed FortiOS build, restore only required services, and retain before-and-after evidence.

Authoritative reference

QCS Editorial Advisory Desk

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source