CVE-2026-24018
published 2026-03-10CVE-2026-24018: A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a…
PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.5th percentile
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlient | >= 7.2.2 < 7.2.13 | 7.2.13 |
| fortinet | forticlient | >= 7.4.0 < 7.4.5 | 7.4.5 |
| fortinet | forticlientlinux | — | — |
| fortinet | forticlientlinux | 7.2.2 – 7.2.12 | — |
| fortinet | forticlientlinux | 7.4.0 – 7.4.4 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g7vg-vfvv-mr49: A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7
ghsa_unreviewed·2026-03-10
CVE-2026-24018 [HIGH] CWE-61 GHSA-g7vg-vfvv-mr49: A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
Fortinet
Local privilege escalation via improper symlink following
vendor_fortinet·2026-03-10·CVSS 7.8
CVE-2026-24018 [HIGH] CWE-61 Local privilege escalation via improper symlink following
FG-IR-26-083: Local privilege escalation via improper symlink following
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
CVEs: CVE-2026-24018
CWEs: CWE-61
CVSS: 7.8 (high)
Affected products: FortiClient, FortiClientLinux, Fortinet
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-24018 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-24018 [HIGH] CVE-2026-24018 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24018 :
FortiClient vulnerability analysis and mitigation
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
FortiClient
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:fortinet:forticlient
Sources
Linux Severity HIGH Has Fix Added at: Mar 14, 2026
Windows Severity HIGH Has Fix Added at: Mar 14, 2026
Linux Severity HIGH
Wiz
CVE-2025-62676 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-62676 [HIGH] CVE-2025-62676 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-62676 :
FortiClient vulnerability analysis and mitigation
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.
Source : NVD
## 7.1
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
FortiClient
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:fortinet
2026-03-10
Published