Fortinet FortiClient Vulnerabilities & Security Advisories
8 advisories tracked · FortiGuard PSIRT Advisories · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Fortinet advisory that VulniPulse classified as FortiClient, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 2 critical, 4 high, 1 medium, 1 low.
Android app · Google Play
Monitor Fortinet CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
FortiGuard PSIRT Advisories
Polled via the official FortiGuard PSIRT RSS feed (filestore.fortinet.com). PSIRT pages are fetched for new items to extract affected and fixed versions.
Latest Fortinet FortiClient advisories
Critical [CVE-2026-35616] API authentication and authorization bypass
CVSSv3 Score: 9.1 An Improper Access Control vulnerability [CWE-284] in FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Fortinet has observed this to be exploited in the wild and urges vulnerable customers to install the hotfix for FortiClient EMS 7.4.5 and 7.4.6, by following the instructions at: - for FortiClientEMS 7.4.5https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484 - for FortiClientEMS 7.4.6Upcoming FortiClientEMS 7.4.7 will also include a fix for this issue. In the meantime the hotfix above is sufficient to prevent it entirely. Revised on 2026-04-04 00:00:00
Critical [CVE-2026-21643] improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS…
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.