fortiguard.fortinet.com
https://fortiguard.fortinet.com/psirt/FG-IR-26-156 CVE-2026-70465
HIGH
Fortinet FortiClientWindows Classic Buffer Overflow Remote Code Execution
Record summary
CVE-2026-70465 has a selected CVSS score of 7.3 (high).
Description
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FortiClientWindowsBrowse Fortinet / FortiClientWindowsDefault status: unaffected | CVE List | 7.4.0 to ≤ 7.4.3 | affected |
| 7.2.0 to ≤ 7.2.11 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-70465