CVE-2026-24018: Fortinet FortiClient

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.

Affected products

  • Fortinet FortiClient: from 7.2.2, before 7.2.13 (fixed in 7.2.13); from 7.4.0, before 7.4.5 (fixed in 7.4.5)

Published 2026-03-10. Last modified 2026-06-17.