← All Advisories

Fortinet FortiClient's Classic Buffer Overflow Allows an Attacker to Corrupt Memory and Potentially Execute Arbitrary Code

Last refreshed2026-09-27

Status: UPDATED  |  Advisory ID: CVE-2026-70465

Key Details

CVECVE-2026-70465
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-09-20
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsFortinet FortiClient
Classified asCWE-120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
Exploitation prediction (EPSS)0.52% probability of exploitation in the next 30 days (42% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
FortinetFortiClient
SubsystemsGeneral OT
SectorsMulti-sector

What to Know

A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.

What to Do

Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-70465
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-70465
Vendor advisoryhttps://fortiguard.fortinet.com/psirt/FG-IR-26-156