Fortinet FortiClient Vulnerabilities & Security Advisories
8 advisories tracked · FortiGuard PSIRT Advisories · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Fortinet advisory that VulniPulse classified as FortiClient, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 2 critical, 4 high, 1 medium, 1 low.
Android app · Google Play
Monitor Fortinet CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
FortiGuard PSIRT Advisories
Polled via the official FortiGuard PSIRT RSS feed (filestore.fortinet.com). PSIRT pages are fetched for new items to extract affected and fixed versions.
Latest Fortinet FortiClient advisories
High [CVE-2026-39809] Multiple SQL Injections
CVSSv3 Score: 7.1 An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiClientEMS may allow an authenticated attacker to run arbitrary SQL queries on the database via sending crafted requests. Revised on 2026-04-14 00:00:00
High [CVE-2026-24018] UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2…
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
High [CVE-2025-62676] FortiClient: Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet…
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.
High [CVE-2025-59922] FortiClient: improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in…
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0 all versions may allow an authenticated attacker with at least read-only admin permission to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.