CVE-2026-44278
- EPSS 0.01%
- Veröffentlicht 12.05.2026 16:54:09
- Zuletzt bearbeitet 16.05.2026 01:59:57
A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>
CVE-2026-24018
- EPSS 0.02%
- Veröffentlicht 10.03.2026 16:44:14
- Zuletzt bearbeitet 13.03.2026 19:04:40
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
CVE-2025-62676
- EPSS 0.01%
- Veröffentlicht 10.02.2026 15:39:12
- Zuletzt bearbeitet 12.02.2026 16:06:17
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local ...
CVE-2025-54660
- EPSS 0.02%
- Veröffentlicht 18.11.2025 17:01:18
- Zuletzt bearbeitet 20.11.2025 14:35:11
An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve the saved ...
CVE-2025-46373
- EPSS 0.02%
- Veröffentlicht 18.11.2025 17:01:15
- Zuletzt bearbeitet 16.12.2025 11:15:52
A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to execute arbitrary code or commands via "forti...
CVE-2025-47761
- EPSS 0.02%
- Veröffentlicht 18.11.2025 17:01:11
- Zuletzt bearbeitet 16.12.2025 11:15:52
An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local user to execute unauthorized code via ...
CVE-2025-46774
- EPSS 0.01%
- Veröffentlicht 14.10.2025 15:23:47
- Zuletzt bearbeitet 22.10.2025 16:47:22
An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related ...
CVE-2025-31365
- EPSS 0.09%
- Veröffentlicht 14.10.2025 15:23:43
- Zuletzt bearbeitet 15.10.2025 17:30:38
An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user ...
CVE-2025-57716
- EPSS 0.02%
- Veröffentlicht 14.10.2025 15:23:10
- Zuletzt bearbeitet 15.10.2025 17:21:15
An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the ...
CVE-2025-57741
- EPSS 0.02%
- Veröffentlicht 14.10.2025 15:22:49
- Zuletzt bearbeitet 15.10.2025 17:23:46
An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local attacker to run arbitrary code or commands via LaunchDaemon hijacking.