CVE-2025-54660
published 2025-11-18CVE-2025-54660: An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.14%
3.6th percentile
An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve the saved VPN user password
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlient | >= 7.0.0 < 7.2.11 | 7.2.11 |
| fortinet | forticlient | >= 7.4.0 < 7.4.4 | 7.4.4 |
| fortinet | forticlientwindows | — | — |
| fortinet | forticlientwindows | 7.0.0 – 7.0.14 | — |
| fortinet | forticlientwindows | 7.2.0 – 7.2.10 | — |
| fortinet | forticlientwindows | 7.4.0 – 7.4.3 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through...
vendor_fortinet·2025-11-18·CVSS 5.5
CVE-2025-54660 [MEDIUM] CWE-489 An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through...
FG-IR-25-844: An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through...
An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve the saved VPN user password
CVEs: CVE-2025-54660
CWEs: CWE-489
CVSS: 5.5 (medium)
Affected products: FortiClient, FortiClientWindows, Fortinet
GHSA
GHSA-9qhw-j8ww-5hqr: An active debug code vulnerability in Fortinet FortiClientWindows 7
ghsa_unreviewed·2025-11-18
CVE-2025-54660 [MEDIUM] CWE-489 GHSA-9qhw-j8ww-5hqr: An active debug code vulnerability in Fortinet FortiClientWindows 7
An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve the saved VPN user password
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-24018 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-24018 [HIGH] CVE-2026-24018 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24018 :
FortiClient vulnerability analysis and mitigation
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
FortiClient
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:fortinet:forticlient
Sources
Linux Severity HIGH Has Fix Added at: Mar 14, 2026
Windows Severity HIGH Has Fix Added at: Mar 14, 2026
Linux Severity HIGH
Wiz
CVE-2025-62676 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-62676 [HIGH] CVE-2025-62676 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-62676 :
FortiClient vulnerability analysis and mitigation
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.
Source : NVD
## 7.1
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
FortiClient
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:fortinet
2025-11-18
Published