CVE-2025-22859: Fortinet FortiClient EMS
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests.
Affected products
- Fortinet FortiClient EMS: from 7.4.0, before 7.4.3 (fixed in 7.4.3)
- Fortinet Forticlientems Cloud: from 7.4.0, before 7.4.3 (fixed in 7.4.3)
Published 2025-05-13. Last modified 2026-06-17.