CVE-2026-59836: Fortinet FortiClient EMS

Critical severity, CVSS 9.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>

Affected products

  • Fortinet FortiClient EMS: from 7.2.0, up to and including 7.4.1; from 7.4.3, before 7.4.6 (fixed in 7.4.6)

Published 2026-07-14. Last modified 2026-07-15.