CVE-2025-46774: Fortinet FortiClient
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related executables.
Affected products
- Fortinet FortiClient: from 7.0.0, before 7.2.10 (fixed in 7.2.10); from 7.4.0, before 7.4.4 (fixed in 7.4.4)
Published 2025-10-14. Last modified 2026-10-08.