cbcvebase.
CVE-2026-44278
published 2026-05-12

CVE-2026-44278: A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker…

PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.10%
0.9th percentile
A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via

Affected

3 ranges
VendorProductVersion rangeFixed in
fortinetforticlient>= 7.2.0 < 7.4.37.4.3
fortinetforticlientwindows7.2.0 – 7.2.14
fortinetforticlientwindows7.4.0 – 7.4.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.