Skip to content
VulniPulse

Fortinet FortiClient Vulnerabilities & Security Advisories

13 advisories tracked · FortiGuard PSIRT Advisories · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Fortinet advisory that VulniPulse classified as FortiClient, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 2 critical, 6 high, 4 medium, 1 low.

Android app · Google Play

Monitor Fortinet CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

FortiGuard PSIRT Advisories

Polled via the official FortiGuard PSIRT RSS feed (filestore.fortinet.com). PSIRT pages are fetched for new items to extract affected and fixed versions.

Latest Fortinet FortiClient advisories

Medium4.7Fortinet

Medium [CVE-2026-84386] unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector here>

A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control

CVE-2026-84386
FortiClient
Sep 8, 2026
Medium4.7Fortinet

Medium [CVE-2026-84386] Arbitrary process termination from exposed minifilter communication port

CVSSv3 Score: 4.7 An Unverified Ownership Vulnerability [CWE-283] in FortiClient Windows fortimon3 driver may allow an authenticated attacker to terminate arbitrary processes via an exposed minifilter communication port. Revised on 2026-09-08 00:00:00 Affected product named by the advisory: FortiClientWindows.

CVE-2026-84386
FortiClient
Sep 8, 2026
Medium6.7Fortinet

Medium [CVE-2026-59836] Missed certificate verification in AD Connector communication with FortiClient EMS

CVSSv3 Score: 6.7 An Improper Certificate Validation vulnerability [CWE-295] in FortiClient EMS may allow a remote unauthenticated attacker to impersonate an AD Connector via a valid API Key. Revised on 2026-07-14 00:00:00 Affected product named by the advisory: FortiClientEMS.

CVE-2026-59836
FortiClient
Jul 14, 2026
Medium5.2Fortinet

Medium [CVE-2026-39810] Hardcoded symmetric encryption key for Postgresql

CVSSv3 Score: 5.2 A use of hard-coded cryptographic key vulnerability [CWE 321] in FortiClientEMS may allow an attacker in possession of an encrypted dump of the database to decrypt it. Revised on 2026-04-14 00:00:00

CVE-2026-39810
FortiClient
Apr 14, 2026

← All Fortinet advisories