Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.1) | 0.14% | — | Fortinet Forticlient WindowsAI | 8/9/2026 | 2/10/2026 | A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via via an exposed minifilter communication port. | |
| Analizada | Alta (8.1) | 0.52% | — | Fortinet Forticlient | 12/8/2026 | 8/9/2026 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via… | |
| Analizada | Crítica (9.8) | 0.22% | — | Fortinet Forticlientems | 14/7/2026 | 15/7/2026 | A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here> | |
| Analizada | Media (5.5) | 0.14% | — | Fortinet Forticlient | 12/5/2026 | 17/6/2026 | A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert attack vector here> | |
| Analizada | Media (5.5) | 0.15% | — | Fortinet Forticlientems | 14/4/2026 | 17/6/2026 | A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump. | |
| Analizada | Media (6.7) | 0.20% | — | Fortinet Forticlientems | 14/4/2026 | 17/6/2026 | A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requests | |
| Analizada | Crítica (9.8) | 9.1% | ⚠ Explotación activa | Fortinet Forticlientems | 4/4/2026 | 24/7/2026 | A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. | |
| Analizada | Alta (7.8) | 0.23% | — | Fortinet Forticlient | 10/3/2026 | 17/6/2026 | A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root. | |
| Analizada | Alta (7.1) | 0.23% | — | Fortinet Forticlient | 10/2/2026 | 17/6/2026 | An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with… | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa | Fortinet Forticlientems | 6/2/2026 | 17/6/2026 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | |
| Analizada | Alta (7.2) | 7.8% | — | Fortinet Forticlientems | 13/1/2026 | 17/6/2026 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0 all versions may allow an authenticated attacker with… | |
| Analizada | Media (5.5) | 0.15% | — | Fortinet Forticlient | 18/11/2025 | 17/6/2026 | An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve the saved VPN user password | |
| Modificada | Alta (7.8) | 0.16% | — | Fortinet Forticlient | 18/11/2025 | 17/6/2026 | An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local user to execute unauthorized code via fortips driver. Success of the attack would require bypassing the… | |
| Modificada | Alta (7.8) | 0.15% | — | Fortinet Forticlient | 18/11/2025 | 17/6/2026 | A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to execute arbitrary code or commands via "fortips_74.sys". The attacker would need to bypass the Windows heap… | |
| Analizada | Alta (7.8) | 0.13% | — | Fortinet Forticlient | 14/10/2025 | 17/6/2026 | An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local attacker to run arbitrary code or commands via LaunchDaemon hijacking. | |
| Analizada | Alta (7.3) | 0.18% | — | Fortinet Forticlient | 14/10/2025 | 17/6/2026 | An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer installation folder. | |
| Analizada | Alta (7.8) | 0.08% | — | Fortinet Forticlient | 14/10/2025 | 17/6/2026 | An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related executables. | |
| Analizada | Alta (7.1) | 0.28% | — | Fortinet Forticlient | 14/10/2025 | 17/6/2026 | An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user into visiting a malicious website. | |
| Analizada | Media (6.5) | 0.17% | — | Fortinet Forticlient | 10/6/2025 | 17/6/2026 | A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection. | |
| Analizada | Media (4.8) | 0.33% | — | Fortinet Forticlientems | 10/6/2025 | 17/6/2026 | An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests. | |
| Analizada | Media (4.3) | 0.34% | — | Fortinet Forticlientems | 10/6/2025 | 17/6/2026 | A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests. | |
| Analizada | Alta (7.8) | 0.19% | — | Fortinet Forticlient | 28/5/2025 | 17/6/2026 | An Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 may allow a local attacker to escalate privileges via crafted XPC messages. | |
| Modificada | Baja (3.7) | 0.55% | — | Fortinet Forticlient | 28/5/2025 | 17/6/2026 | A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an unauthorized remote attacker to view application information via navigation to a hosted webpage, if Windows is configured… | |
| Analizada | Media (5.3) | 0.58% | — | Fortinet ForticlientemsFortinet Forticlientems Cloud | 13/5/2025 | 17/6/2026 | A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests. | |
| Analizada | Alta (7.8) | 0.14% | — | Fortinet ForticlientFortinet Fortifone Softclient | 13/5/2025 | 17/6/2026 | An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables. |