Status: UPDATED
| Advisory ID: CVE-2026-70465
Key Details
| CVE | CVE-2026-70465 |
| CVSS Score / Version | 8.1 (High) / CVSS v3.1 |
| Updated | 2026-09-20 |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Fortinet FortiClient |
| Classified as | CWE-120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')) |
| Exploitation prediction (EPSS) | 0.52% probability of exploitation in the next 30 days (42% percentile) -- FIRST.org's EPSS model. |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multi-sector |
What to Know
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.
What to Do
Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.
References