CVE-2025-62676
published 2026-02-10CVE-2025-62676: An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4…
PriorityP335high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.21%
11.8th percentile
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlient | >= 7.0.0 < 7.2.13 | 7.2.13 |
| fortinet | forticlient | >= 7.4.0 < 7.4.5 | 7.4.5 |
| fortinet | forticlientwindows | — | — |
| fortinet | forticlientwindows | 7.0.0 – 7.0.14 | — |
| fortinet | forticlientwindows | 7.2.0 – 7.2.12 | — |
| fortinet | forticlientwindows | 7.4.0 – 7.4.4 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8cg4-rqg8-pcg3: An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7
ghsa_unreviewed·2026-02-10
CVE-2025-62676 [HIGH] CWE-59 GHSA-8cg4-rqg8-pcg3: An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.
Fortinet
Arbitrary XML file write in FCConfig
vendor_fortinet·2026-02-10·CVSS 7.1
CVE-2025-62676 [HIGH] CWE-59 Arbitrary XML file write in FCConfig
FG-IR-25-661: Arbitrary XML file write in FCConfig
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.
CVEs: CVE-2025-62676
CWEs: CWE-59
CVSS: 7.1 (high)
Affected products: FortiClient, FortiClientWindows, Fortinet
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-24018 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-24018 [HIGH] CVE-2026-24018 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24018 :
FortiClient vulnerability analysis and mitigation
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
FortiClient
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:fortinet:forticlient
Sources
Linux Severity HIGH Has Fix Added at: Mar 14, 2026
Windows Severity HIGH Has Fix Added at: Mar 14, 2026
Linux Severity HIGH
Wiz
CVE-2025-62676 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-62676 [HIGH] CVE-2025-62676 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-62676 :
FortiClient vulnerability analysis and mitigation
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.
Source : NVD
## 7.1
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
FortiClient
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:fortinet
2026-02-10
Published