HTTP/2 Memory Exhaustion Denial-of-Service Vulnerability in Fortinet FortiProxy, FortiPAM, and FortiSwitch Manager
Security Advisory Brief
Fortinet has published a security advisory, tracked as FG-IR-26-163, disclosing that several of its network security and privileged access products inherit a denial-of-service vulnerability from the Apache HTTP Server component embedded in their web-facing services. The flaw, identified as CVE-2026-49975 and publicly nicknamed the "HTTP/2 Bomb," resides in the mod_http2 module of Apache HTTP Server and allows an unauthenticated remote attacker to exhaust the memory of an affected system using specially crafted HTTP/2 requests. Fortinet published the advisory on August 12, 2026, and has confirmed that FortiProxy, FortiPAM, and FortiSwitch Manager are affected across multiple release branches.
The underlying weakness is classified as CWE-789, Memory Allocation with Excessive Size Value, and is compounded by CWE-409, Improper Handling of Highly Compressed Data. An attacker sends a small volume of crafted HTTP/2 header frames that the server expands into a disproportionately large memory allocation, a data amplification pattern that allows a single connection to consume gigabytes of memory on the target. Because the exchange occurs during HTTP/2 request handling and before any authentication takes place, exploitation requires nothing more than network reachability to a listening service with HTTP/2 enabled. The National Vulnerability Database assigns CVE-2026-49975 a CVSS v3.1 base score of 7.5, reflecting an availability-only impact with no loss of confidentiality or integrity, while Fortinet assigns a product-context CVSS v3.1 score of 5.8 based on the more limited availability degradation observed within its own appliance architecture. Neither NIST nor Fortinet has published a CVSS v4.0 score for this vulnerability.
The risk to organizations is driven less by the severity rating than by the exposure profile of the affected products and the maturity of the available exploit tooling. FortiProxy is a secure web gateway commonly deployed at the internet edge, FortiPAM brokers privileged administrative sessions to critical infrastructure, and FortiSwitch Manager provides centralized control of switching fabric — each is a control point whose loss of availability degrades far more than a single host. Fortinet's advisory records no known exploitation of this issue in its products at the time of publication, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. However, Fortinet's own scoring vector marks the exploit code maturity as functional, and working proof-of-concept code for the upstream Apache flaw has been published on public code repositories since the June 2026 disclosure, which materially shortens the window between disclosure and opportunistic exploitation.
Threats and Vulnerabilities
CVE-2026-49975, with a CVSS v3.1 base score of 7.5 as published by NIST and a vendor-assigned CVSS v3.1 score of 5.8 in Fortinet's product context, is a memory allocation flaw in the mod_http2 module of Apache HTTP Server affecting upstream versions 2.4.17 through 2.4.67. The vulnerability allows a remote, unauthenticated attacker to trigger an excessive memory allocation by submitting malicious HTTP/2 requests, causing the server process to consume available memory and stop servicing legitimate traffic. The amplification characteristic is what distinguishes this issue from conventional volumetric denial of service — the attacker does not need to generate significant bandwidth or sustain a botnet, because a small number of compact header frames on a single connection is sufficient to pin a disproportionate quantity of memory on the target. The Apache Software Foundation addressed the flaw in Apache HTTP Server 2.4.68, and Fortinet has ported the corrected component into its product releases. The same underlying HTTP/2 amplification technique was disclosed as affecting multiple independent server implementations beyond Apache, indicating a class of protocol-handling weakness rather than an isolated coding defect.
Within the Fortinet portfolio, the affected products and version ranges are specific and should be checked against deployed inventory directly. FortiPAM is affected in versions 1.9.0 through 1.9.1, and in all versions of the 1.0 through 1.8 branches. FortiProxy is affected in versions 7.6.0 through 7.6.6, in versions 7.4.0 through 7.4.14, and in all versions of the 7.2 branch. FortiSwitch Manager is affected in versions 7.2.0 through 7.2.9. Fortinet directs administrators to upgrade FortiPAM to 1.9.2 or above, FortiProxy to 7.6.7 or above on the 7.6 branch and 7.4.15 or above on the 7.4 branch, and FortiSwitch Manager to 7.2.10 or above. Organizations running FortiPAM 1.0 through 1.8 or FortiProxy 7.2 are directed to migrate to a fixed release, as no corrective build is being issued for those branches. Fortinet documents no configuration workaround for this vulnerability, which means remediation depends entirely on version upgrade or on network-level restriction of access to the affected services.
An operational constraint deserves particular attention. At the time Fortinet published this advisory, each of the designated fixed builds — FortiPAM 1.9.2, FortiProxy 7.6.7 and 7.4.15, and FortiSwitch Manager 7.2.10 — was described as an upcoming release rather than one already available for download. Organizations should therefore verify current availability on the Fortinet support portal before planning a maintenance window, and should treat compensating network controls as the operative near-term measure for any affected system whose fixed build has not yet shipped. This gap between disclosure and patch availability, combined with the existence of public exploit code for the upstream Apache defect, is the principal reason this advisory warrants action ahead of its moderate severity rating.
Client Impact
The operational consequence of successful exploitation is loss of availability of the affected device, and the significance of that loss scales with the role the device plays. A FortiProxy instance rendered unresponsive interrupts outbound web access and the inspection of that traffic for an entire user population, and depending on failure mode may either block traffic entirely or drive a bypass condition in which traffic flows without inspection. A FortiPAM outage severs the brokered path administrators use to reach privileged systems, which is especially consequential during an active incident when that path is the mechanism responders depend on. A FortiSwitch Manager outage removes centralized visibility and configuration control over the switching fabric, degrading the ability to segment or isolate a network segment at the moment isolation is most likely to be needed. For organizations operating industrial or operational technology environments, where these products frequently mediate the boundary between enterprise and control networks, an availability failure at that boundary can force a conservative shutdown of the crossing itself.
From a compliance and governance perspective, the exposure is straightforward to characterize but should not be treated as routine. Frameworks including NERC CIP, IEC 62443, and the NIST Cybersecurity Framework place explicit obligations on the timely evaluation and remediation of known vulnerabilities in systems that perform access control or network segmentation functions, and each of the affected products falls into that category in typical deployments. Where a fixed build is not yet available, most of these frameworks accommodate documented compensating controls, but they require that the mitigation decision, its technical basis, and its review date be recorded rather than assumed. Organizations subject to incident reporting obligations should also recognize that an availability outage on a segmentation or privileged-access control point may itself meet a reporting threshold, independent of whether any data was accessed. Documenting the affected inventory, the interim controls applied, and the planned upgrade date is the practical step that satisfies auditor inquiry on this advisory.
Mitigations
The following actions are recommended to reduce exposure to CVE-2026-49975 across affected Fortinet deployments:
- Inventory all FortiProxy, FortiPAM, and FortiSwitch Manager instances and record the exact running firmware version for each, comparing against the affected ranges — FortiPAM 1.0 through 1.9.1, FortiProxy 7.2 through 7.6.6, and FortiSwitch Manager 7.2.0 through 7.2.9 — rather than relying on a general assumption that a recent build is unaffected.
- Upgrade affected systems to the corrected releases as soon as those builds are available from the Fortinet support portal: FortiPAM 1.9.2 or above, FortiProxy 7.6.7 or above and 7.4.15 or above, and FortiSwitch Manager 7.2.10 or above. For FortiPAM 1.0 through 1.8 and FortiProxy 7.2, plan a migration to a supported branch, as no fix is being issued for those releases.
- Restrict network reachability to the administrative and web-facing interfaces of affected devices until patching is complete, permitting access only from designated management networks and jump hosts. Because exploitation requires only the ability to open an HTTP/2 connection to the service, limiting who can reach that listener is the most effective interim control available in the absence of a vendor workaround.
- Where the deployment architecture permits and HTTP/2 is not operationally required on an exposed listener, evaluate disabling HTTP/2 negotiation on upstream load balancers or reverse proxies fronting the affected devices, so that connections downgrade to HTTP/1.1 and the vulnerable request-handling path is not reached.
- Establish monitoring for the failure signature rather than for the exploit alone — alert on abnormal memory utilization, process restarts, and unexpected service unavailability on the affected appliances, and review HTTP/2 connection patterns from external sources for a small number of connections producing disproportionate resource consumption. These indicators are observable even where the crafted request itself is not logged.
Applying these measures in sequence — establishing an accurate inventory, restricting reachability immediately, and upgrading as builds become available — provides layered risk reduction during the interval in which fixed firmware is pending.
1898 & Co. Response
1898 & Co. has extensive experience supporting critical infrastructure operators in evaluating vendor advisories of this kind and translating them into prioritized, executable remediation activity. Our security consultants work alongside client teams to identify affected assets across enterprise and operational technology environments, assess the practical exposure of each instance based on its network position and reachability, and determine where interim network controls provide adequate risk reduction while firmware updates are pending. This approach recognizes that the appropriate response to a vulnerability in a segmentation or privileged-access device depends substantially on where that device sits and what it protects.
Our Managed Threat Detection and Response service maintains continuous monitoring across client IT and OT environments, with detection engineering focused on the behavioral consequences of exploitation rather than solely on signature matching. For availability-impacting vulnerabilities such as this one, that means monitoring for the resource exhaustion and service interruption patterns that indicate a denial-of-service condition in progress, and correlating those events with perimeter telemetry to distinguish an attack from an operational fault. Our analysts have supported clients through numerous vendor advisory cycles affecting network security appliances and understand the operational sensitivity of patching devices that sit in the traffic path.
Beyond immediate response to this advisory, 1898 & Co. assists organizations in strengthening the underlying processes that govern vulnerability management for network infrastructure — asset inventory accuracy, vendor advisory intake, exposure analysis, and change management for devices where downtime carries operational consequence. Organizations seeking assistance with assessing exposure to this vulnerability, conducting a threat hunt across affected systems, or reviewing their broader network device patching program are encouraged to contact 1898 & Co. for support.