cbcvebase.
CVE-2026-70465
published 2026-08-12

CVE-2026-70465: A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows…

PriorityP353high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.52%
41.9th percentile
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.

Affected

6 ranges
VendorProductVersion rangeFixed in
fortinetforticlient>= 7.2.0 < 7.2.127.2.12
fortinetforticlient>= 7.4.0 < 7.4.47.4.4
fortinetforticlientwindows——
fortinetforticlientwindows7.2.0 – 7.2.11—
fortinetforticlientwindows7.4.0 – 7.4.3—
fortinetfortinet——
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.